I don't really know how to try those solutions.
I did stumble into below section in web.conf:
override MIME type for JSON data
If this is set to True, the splunkweb appserver will serve up JSON data with
a content-type of "text/plain; charset=UTF-8". This keeps it compatible with previous versions of Splunk.
If this is set to False, the content-type will be "application/json; charset=UTF-8" as is standard.
In a future version of Splunk, this default will change so that the standard content-type
is used consistently between splunkweb endpoints and splunkd endpoints accessed through proxy
override_JSON_MIME_type_with_text_plain = True
Which looked like it has something to do with my issue but after creating a web.conf in $SPLUNKHOME\etc\system\local, change the entry to False and restarting splunk I still have the same issue....
... View more