Splunk Search

Splunk Search Heads in infinite loop of refreshing

dkrichards16
Path Finder

We had one search head have to be rebuilt because of JAVA issues.  We had another search head, due to a network switch outage, loose connection to the search head cluster.

When we re-adding those servers to the search head cluster we not have a strange issue with where custom apps can't search.  They either provided a "error fetching saved searches" in the panel then get stuck in a infinite loop of refreshing the browser tab or they load an error 255 where they can't search indexes even though they can search indexes fine in the default search and reporting app.

We use custom authorization.conf and authorize.conf configs in /opt/splunk/etc/system/local and affected servers have the latest configs copied from a healthy server.  I'm working with splunk support but they are requesting har browser files and the issues seem to be permissions related.  Has anyone else seen this issue and able to resolve it?

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...