Security

Why does splunkweb in 6.6.2 take so long to start?

twinspop
Influencer

I've recently begun upgrading all my servers to 6.6.2 from 6.5.3. It's mostly been smooth, aside from the SSL issues with older builds of OpenSSL.

One thing that really stands out is how long it takes for splunkweb to finish start up. I mean, a crazy long time.

Waiting for web server at https://127.0.0.1:8443 to be available............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................ Done

With 6.5.3 this part of a restart is almost instant every time. What gives?

1 Solution

gjanders
SplunkTrust
SplunkTrust

Have you had a look at Slow splunkweb startup caused by splunk_instrumentation and seeing it that is the same issue or not?

Effectively from that post you could try this if you do not want your Splunk instance going via a proxy to the internet (from the other splunk answer):

On a server which doesn't have access
to the proxy, I just put the following
in my splunk-launch.conf:

 QUICKDRAW_URL=0

View solution in original post

gjanders
SplunkTrust
SplunkTrust

Have you had a look at Slow splunkweb startup caused by splunk_instrumentation and seeing it that is the same issue or not?

Effectively from that post you could try this if you do not want your Splunk instance going via a proxy to the internet (from the other splunk answer):

On a server which doesn't have access
to the proxy, I just put the following
in my splunk-launch.conf:

 QUICKDRAW_URL=0

twinspop
Influencer

Thank you. I missed that post in my searching. The QUICKDRAW_URL setting is working.

0 Karma

gjanders
SplunkTrust
SplunkTrust

No problem I'm going to report this to the documentation team again as this remains undocumented.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...