Splunk Search

Why does Splunk Web sometimes not show the event data for a search unless I restart?

boopaljothi
Explorer

Splunk Web doesn't show the events at times. If I restart and log in, it will show the events, but after some time, events are not displayed. It shows total events, but the details are not displayed
alt text

Also, the main page doesn't show the summary of events indexed. Usually it should total events and indexes.

alt text

What could be the problem? This leads to me restarting splunkd service every time.

1 Solution

vasanthmss
Motivator

... | table _raw
check Wats there. If your logs are json Splunk will take time to load... Post the screen shot

V

View solution in original post

AzJimbo
Path Finder

this old problem bit me today.  Go to 'All Fields' and deselect all fields, then close that window.    Once that was settled, I was able to reselect the 'All Fields' option and the Event Viewer repopulated.  Not sure why it worked, but it did and thought I'd share.

CONSORP
Loves-to-Learn Lots

There's also a possible chance of exceeding truncate value and browser will not be able to render and support UI, check length of your _raw event using <your search query>| eval len=len(_raw) and view field len under interesting fields.

0 Karma

2santanudey
New Member

This is real pain. sometime logs are coming and most of the time same query/index does not show any result. Since we are using this across enterprise, it's not possible to restart or play around with this tool. Not happy with splunk. Need to time to think of another solution.

0 Karma

chimell
Motivator

Hi boopaljothi
I advice you to use another browser to launch you search and wait a few minutes before concluding.

0 Karma

boopaljothi
Explorer

i used internet explorer latest version and it is working. may be an issue with chrome. i will update chrome and post the status here

0 Karma

Ramesh_Yedurla
Engager

yes change the browser

0 Karma

vasanthmss
Motivator

... | table _raw
check Wats there. If your logs are json Splunk will take time to load... Post the screen shot

V

boopaljothi
Explorer

there is no output for this as well. i cant attach file here as of now

0 Karma

vasanthmss
Motivator

| head 1| table _raw

Check it.

index=_internal error

...
Wats the index and sourcetype it source you are using.Can you share the sample data

V
0 Karma

boopaljothi
Explorer

nope still no output

0 Karma

vasanthmss
Motivator

Wat browser you are using.?
I guess tat should be supported by Splunk. If you are not getting internal logs.there should be a problem with your browser. Use chrome or mozilla

V
0 Karma

boopaljothi
Explorer

i am using chrome only.

index=_internal error this is returning error but there is no output to the head 1| table _raw output for my own query. sorry for the confusion

0 Karma

vasanthmss
Motivator

Try with chrome

V
0 Karma

yannK
Splunk Employee
Splunk Employee

if you see the number of results counter, but no events displayed in the panel, this may be a UI rendering issue.
Maybe some events contain characters that breaks the display.

Do you see results if you use a stats command or a chart ?
Check for the javascript logs of your browser (developper tool on chrome by example)
And try to look for a different set of events.

ben_leung
Builder

I have some users that complain about the same issue. I had advised them to clear their cache, tried different web browsers, nothing works for them. Similar to the screenshot in the post, there is data in the timeline and the fields column display, but the events in the table do not show anything.

Trying to debug from the access logs and what I could find in Splunk internal logs, there is nothing out of the ordinary. HELP

0 Karma

cneberg
Explorer

My solution was go into the "All Fields" button on the left of the search results, change Coverage: From "All fields", to something smaller, and hit deselect all. Then run a simple search to make sure things are coming up, then go back and select just specific fields and everything starts to work. My best guess is that at some point - I had it select a huge number of fields, and doing these changes forces it to forget the huge list which fixes the issue.

0 Karma

jonwentworth
Engager

cneberg's solution works for me - both on chrome and safari - "Coverage: 1% or more" and deselect - events magically appear!

0 Karma

boopaljothi
Explorer

i am searching all the events that i have which is just under 100. i did try with stats command but still nothing just count was displayed as before

0 Karma

boopaljothi
Explorer

any help here. this becoming too difficult

0 Karma

boopaljothi
Explorer

also i imported the tutorial data only and no other events are present. still i get same issue

0 Karma
Get Updates on the Splunk Community!

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...