Installation

Search heads cannot connect to web login after 8.0 upgrade

willsy
Communicator

Hello. After upgrading from 7.3 to 8.01 my search heads no longer work.

It will not load up the search head web page.

Any ideas?

If I load from a backup back to 7.3 all of my real time indexed data is there and still working and I can search it all.

If no ideas. Is there a way to keep the config but apply it to a new search head? Effectively rebuilding the search head from scratch but with a 8.01 build on it?

Either will suffice.

Many thanks in advance

Labels (2)
0 Karma
1 Solution

willsy
Communicator

Hello,

Just to confirm I have sold the problem.

So after I upgraded my search heads to 8.01 I noticed I could not see the web GUI. I looked at my splunkd.log and said my application server was at fault. I don't have an application server but this I took for my deployment server but that it was an application that was the issue.

i looked at the web_service.log and noticed down the bottom that there was a particular application stopping my whole search head environment from working. For me this was the splunk for nix application and TA.

steps i did to rectify the issue.

1) looked into splunkd.log and saw the application server fault
2) looked into web_services.log and it literally told me which application was at fault
3) i stopped my search heads and deployment server
4) on the deployment server i moved the unix application into disabled applications
5) on the unix application app.conf i also set it to disable to make sure.
6) restarted my deployment server
7) restarted my search heads
8) logged into my search head web GUI

if anyone is having a similar issue i can go into detail of files etc. but yea, all sorted.

View solution in original post

0 Karma

willsy
Communicator

Hello,

Just to confirm I have sold the problem.

So after I upgraded my search heads to 8.01 I noticed I could not see the web GUI. I looked at my splunkd.log and said my application server was at fault. I don't have an application server but this I took for my deployment server but that it was an application that was the issue.

i looked at the web_service.log and noticed down the bottom that there was a particular application stopping my whole search head environment from working. For me this was the splunk for nix application and TA.

steps i did to rectify the issue.

1) looked into splunkd.log and saw the application server fault
2) looked into web_services.log and it literally told me which application was at fault
3) i stopped my search heads and deployment server
4) on the deployment server i moved the unix application into disabled applications
5) on the unix application app.conf i also set it to disable to make sure.
6) restarted my deployment server
7) restarted my search heads
8) logged into my search head web GUI

if anyone is having a similar issue i can go into detail of files etc. but yea, all sorted.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...