Getting Data In

Why am I getting "ERROR UiPythonFallback - Appserver at http://127.0.0.1:8065 never started up!" on my Splunk 6.2.1 indexers?

richardwii
Engager

I am new to Splunk, and noticed the web interface for my Indexers is offline.

After reviewing the logs I found the below error messages:

ERROR UiPythonFallback - Appserver at http://127.0.0.1:8065 never started up!
ERROR UiPythonFallback - Couldn't start any appserver processes, UI will probably not function correctly!

Initially there was a duplicate application error, with a _cluster directory present in different app directories.
Following the answers to another question I clean all of _cluster directories up.

This does not impact my heavy forwarders, only the indexers.
I'm using a RHEL VP on AWS running Splunk 6.2.1

Any help would be greatly appreciated.

Thanks in Advance
Richard

matthewpearce
Explorer

I was stuck on this error for a long time. When I removed the last application that I installed from /apps/splunk/etc/apps/ and restarted splunk, it came up fine. I suspect there was an issue with the latest App that I tried to install. Manually removing and restarting seemed to fix it.

0 Karma

ThomasKoeberlei
Explorer

If your AWS machine is offline, this could help:
splunk-launch.conf:

QUICKDRAW_URL=0

https://answers.splunk.com/answers/545000/slow-splunkweb-startup-caused-by-splunk-instrument.html

0 Karma

briancrandall
Explorer

I ran into a similar set of errors in my AWS logs. When I tried to connect to the web interface, I would get a response of "500 No appservers running." The root cause turned out to be auditd hogging disk I/O. Not sure if you have the same issue, but you might try disabling the auditd service and see if that does anything.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...