Splunk Search

Splunk Search Heads in infinite loop of refreshing

dkrichards16
Path Finder

We had one search head have to be rebuilt because of JAVA issues.  We had another search head, due to a network switch outage, loose connection to the search head cluster.

When we re-adding those servers to the search head cluster we not have a strange issue with where custom apps can't search.  They either provided a "error fetching saved searches" in the panel then get stuck in a infinite loop of refreshing the browser tab or they load an error 255 where they can't search indexes even though they can search indexes fine in the default search and reporting app.

We use custom authorization.conf and authorize.conf configs in /opt/splunk/etc/system/local and affected servers have the latest configs copied from a healthy server.  I'm working with splunk support but they are requesting har browser files and the issues seem to be permissions related.  Has anyone else seen this issue and able to resolve it?

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Notification Email Migration Announcement

The Notification Team is migrating our email service provider from Postmark to AWS Simple Email Service (SES) ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...