Splunk Search

Why does Splunk Web sometimes not show the event data for a search unless I restart?

Explorer

Splunk Web doesn't show the events at times. If I restart and log in, it will show the events, but after some time, events are not displayed. It shows total events, but the details are not displayed
alt text

Also, the main page doesn't show the summary of events indexed. Usually it should total events and indexes.

alt text

What could be the problem? This leads to me restarting splunkd service every time.

0 Karma
1 Solution

Motivator

... | table _raw
check Wats there. If your logs are json Splunk will take time to load... Post the screen shot

View solution in original post

Loves-to-Learn Lots

There's also a possible chance of exceeding truncate value and browser will not be able to render and support UI, check length of your _raw event using <your search query>| eval len=len(_raw) and view field len under interesting fields.

0 Karma

New Member

This is real pain. sometime logs are coming and most of the time same query/index does not show any result. Since we are using this across enterprise, it's not possible to restart or play around with this tool. Not happy with splunk. Need to time to think of another solution.

0 Karma

Motivator

Hi boopaljothi
I advice you to use another browser to launch you search and wait a few minutes before concluding.

0 Karma

Explorer

i used internet explorer latest version and it is working. may be an issue with chrome. i will update chrome and post the status here

0 Karma

yes change the browser

0 Karma

Motivator

... | table _raw
check Wats there. If your logs are json Splunk will take time to load... Post the screen shot

View solution in original post

Explorer

there is no output for this as well. i cant attach file here as of now

0 Karma

Motivator

| head 1| table _raw

Check it.

index=_internal error

...
Wats the index and sourcetype it source you are using.Can you share the sample data

0 Karma

Explorer

nope still no output

0 Karma

Motivator

Wat browser you are using.?
I guess tat should be supported by Splunk. If you are not getting internal logs.there should be a problem with your browser. Use chrome or mozilla

0 Karma

Explorer

i am using chrome only.

index=_internal error this is returning error but there is no output to the head 1| table _raw output for my own query. sorry for the confusion

0 Karma

Motivator

Try with chrome

0 Karma

Splunk Employee
Splunk Employee

if you see the number of results counter, but no events displayed in the panel, this may be a UI rendering issue.
Maybe some events contain characters that breaks the display.

Do you see results if you use a stats command or a chart ?
Check for the javascript logs of your browser (developper tool on chrome by example)
And try to look for a different set of events.

0 Karma

Builder

I have some users that complain about the same issue. I had advised them to clear their cache, tried different web browsers, nothing works for them. Similar to the screenshot in the post, there is data in the timeline and the fields column display, but the events in the table do not show anything.

Trying to debug from the access logs and what I could find in Splunk internal logs, there is nothing out of the ordinary. HELP

0 Karma

Explorer

My solution was go into the "All Fields" button on the left of the search results, change Coverage: From "All fields", to something smaller, and hit deselect all. Then run a simple search to make sure things are coming up, then go back and select just specific fields and everything starts to work. My best guess is that at some point - I had it select a huge number of fields, and doing these changes forces it to forget the huge list which fixes the issue.

0 Karma

Engager

cneberg's solution works for me - both on chrome and safari - "Coverage: 1% or more" and deselect - events magically appear!

0 Karma

Explorer

i am searching all the events that i have which is just under 100. i did try with stats command but still nothing just count was displayed as before

0 Karma

Explorer

any help here. this becoming too difficult

0 Karma

Explorer

also i imported the tutorial data only and no other events are present. still i get same issue

0 Karma

Legend
0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!