Splunk Search

Splunk Search Heads in infinite loop of refreshing

dkrichards16
Path Finder

We had one search head have to be rebuilt because of JAVA issues.  We had another search head, due to a network switch outage, loose connection to the search head cluster.

When we re-adding those servers to the search head cluster we not have a strange issue with where custom apps can't search.  They either provided a "error fetching saved searches" in the panel then get stuck in a infinite loop of refreshing the browser tab or they load an error 255 where they can't search indexes even though they can search indexes fine in the default search and reporting app.

We use custom authorization.conf and authorize.conf configs in /opt/splunk/etc/system/local and affected servers have the latest configs copied from a healthy server.  I'm working with splunk support but they are requesting har browser files and the issues seem to be permissions related.  Has anyone else seen this issue and able to resolve it?

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...

From Alert to Resolution: How Splunk Observability Helps SREs Navigate Critical ...

It's 3:17 AM, and your phone buzzes with an urgent alert. Wire transfer processing times have spiked, and ...