Splunk Search

splunk is hanging after search

abhayneilam
Contributor

Hi,

I have installed 64 bit splunk-6.0.2 in VM-ware10 in Redhat-6. I have configured everything and restarted the service and it worked fine. But when I am running any search it shows "loading" in the middle of the splunk web and nothing happens even if I wait for hour and hour.
I found the following error from the splunkd.log :

ERROR HTTPClient - Cannot resolve IP of host=splunkbase.splunk.com: Temporary Failure in Name Resolution.
ERROR ApplicationUpdater - Error checking for update, URL=/api/apps:resolve/checkforupgrade: Invalid URI

I have gone through the WIKI of no internet connection but nothing happened. Please provide me the solution as I need to give an urgent delivery ..

Please help !!

Tags (2)
0 Karma

grijhwani
Motivator

The error you have encountered in the log is simply the UI attempting to check for the latest version in order to prompt you to upgrade if appropriate. I would not expect that to cause the session to hang. I have a version 5 search head which has no internet connection, and that hangs only briefly during the attempt (a matter of seconds). I stand to be corrected, though.

What else do you find in any Splunk logs (or indeed in the system logs) around the same time? Have you checked dmesg or looked in /var/log/messages for process faults?

0 Karma

abhayneilam
Contributor

Can any one help me in solving the above issues ? It is paining and did lots of stuffs but nothing is working ..any idea why is this happening ?

0 Karma

abhayneilam
Contributor

/var/log/messages file and dmesg file is not giving any error related to the one which I am facing . just now I have checked it . I am doing internet via dongle in windows machine, so my dmesg and /var/log/messages file is showing some information related to USB.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...