Splunk User Behavior Analytics

Splunk UBA - caspida-ui is dead and pid file exists[FAILED]

kishor_pinjark2
Path Finder

Why Splunk UBA UI is not starting in a cluster?

[caspida@xxxxxxx bin]$ ./Caspida status
IP - xxxxxxx
Mon Dec 28 10:38:48 IST 2020: Running: ./Caspida status
checking status of: caspida-jobmanager
Caspida Job Manager is running[ OK ]
checking status of: caspida-ui
caspida-ui is dead and pid file exists[FAILED]
caspida-ui status: return value: 1
[caspida@xxxxxxx bin]$ ./Caspida start-service caspida-ui
IP - xxxxxxx
Mon Dec 28 10:39:29 IST 2020: Running: ./Caspida start-service caspida-ui
Labels (1)
Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

You can run /opt/caspida/bin/utils/uba_health_check.sh and check the output for errors. If you can find something that may cause splunk ui fails, you should better create a support ticket.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @kishor_pinjark2,

Did you try restarting all services from master node?

[caspida@xxxxxxx bin]$ ./Caspida stop-all

[caspida@xxxxxxx bin]$ ./Caspida start-all

And if works you should check if all live data sources started successfully. On some versions data sources should start manually after restart.

 

İf this reply helps you an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

kishor_pinjark2
Path Finder

Yes, tried stop-all and start-all command many times. Also, server reboot done and start-all command ran.
Still facing same problem.

0 Karma
Get Updates on the Splunk Community!

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...

What's New in Splunk Cloud Platform 9.2.2406?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2406 with many ...

Enterprise Security Content Update (ESCU) | New Releases

In August, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...