Dashboards & Visualizations

Can no longer use any of the links in Settings/Lookups

mlampell
Explorer

I've been using Splunk since 5.0, and upgraded to 6.0 not long ago. I've created Lookup tables in several applications. After a recent upgrade to 6.10, whenever I go to Settings/Lookups (under any application) and try any of the links, trying to review the Lookup tables I had previously set up, I now get the following error message:

 An error occurred while rendering the page template. See web_service.log for more details
 View more information about your request (request ID = 53704412263a13b70) in Search 
 This page was linked to from http://127.0.0.1:8000/en-US/manager/launcher/lookups.

I cannot find any relevant information in web_service.log, nor any reference to the request_id named above.

I'm willing to re-enter the lookup information manually. Is there a way I can reset the sections of the configuration files related to lookup so that this starts working again?

I've seen several references to this type of error message in Answers, but the recommendations are inconclusive.

Tags (2)
0 Karma

mlampell
Explorer

Hi Rsennet_splunk. Thanks for your response. I will address your comments here.

Here is a snippet from the contents of web_service.log while the error occurs:

2014-05-12 11:19:25,039 INFO    [5370e67d066c16128] i18n_catalog:40 - i18ncatalog: translations_retrieved=0.0 etag_calculated=0.0 overall=0.0
2014-05-12 11:19:41,226 INFO    [5370e68d2e428a860] view:1005 - bypass module system fast path
2014-05-12 11:19:41,263 INFO    [5370e68d2e428a860] view:1060 - PERF - viewType=fastpath viewTime=0.076s templateTime=0.001s
2014-05-12 11:19:41,381 INFO    [5370e68d5b6bcde80] i18n_catalog:40 - i18ncatalog: translations_retrieved=0.010999917984 etag_calculated=0.0 overall=0.010999917984
2014-05-12 11:19:50,734 INFO    [5370e696ba3b9b550] i18n_catalog:40 - i18ncatalog: translations_retrieved=0.0 etag_calculated=0.0 overall=0.0
2014-05-12 11:20:11,549 INFO    [5370e6ab7641679b0] view:1005 - bypass module system fast path
2014-05-12 11:20:11,680 INFO    [5370e6ab7641679b0] view:1060 - PERF - viewType=fastpath viewTime=0.213s templateTime=0.002s
2014-05-12 11:20:11,747 INFO    [5370e6abbc3b9b9b0] i18n_catalog:40 - i18ncatalog: translations_retrieved=0.000999927520752 etag_calculated=0.0 overall=0.000999927520752

I don't see anything relevant here. I also get the following hyperlink:

 View more information about your request (request ID = 5370e69cc33e8da90) in Search 

But I don't find that request id in the web_service.log. Furthermore, if I click on the hyperlink, I get sent to the Search window, with the following search typed in:

index=_internal host="41T0KX1" source=*web_service.log log_level=ERROR requestid=5370e69cc33e8da90

But no information is returned, since the requestid doesn't appear.

I tried removing references to "lookup" in transforms.conf and props.conf, but the problem persists. At this point I'm not sure what else to do, I'm considering re-installing splunk.

Similar issues can be seen by entering the following query into google (sorry don’t have enough karma to post a URL):
“An error occurred while rendering the page template. See web_service.log for more details”

However, as can be seen by the age of the entries and the inconclusive responses, it seems that this is being interpreted as an installation -type error or is inconclusive.

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

The info for your lookups are in the props.conf and transforms.conf depending upon what kind of lookup stuff you've configured.

I can't speak to the origins of the error... but it sounds like some wires have crossed regarding permissions. a user would see grey links as opposed to a power user or the admin... or some unique role.

you might want to post the info from that time period regarding the web_service.log.
declaring the contents irrelevant doesn't give anyone anything to work with.
Also... if you saw other references to this issue. You might want to save folks the time of having to look it all up themselves and post the links.

regardless... you can fix it by hand in props.conf and transforms.conf or at the very least, apply whatever changes you wanted to make from there.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...