I'm running splunk 6.3.0, and usually access it with Firefox. But the organization I work for mostly use Internet Explorer on a managed desktop solution, and it turns out that very long log lines in search results seems to cause IE to become non-responding.
The IE version I'm using (and can't upgrade/downgrade to check other versions) is 11.0.9600.18163
The logs in question are sensitive financial database audit logs, so I can't share any actual logs. But they are of the order of 800-1000 characters long, most of which tend to be spaces or dashes. Basically a database schema delta, usually with a huge bunch of blank fields.
All other logs seem to work just fine, but I don't have any other log entries that long, so I'm putting my money on the issue being the length of the log lines.
Symptoms;
If a search results in raw log entries (as apart from stats results etc), and those entries include these database audit logs, then IE freezes, and shows a banner at the bottom saying "url.site is not responding." where url.site is the name of the splunk website without the preceding splunk. EG: our splunk deployment is at https://splunk.company.com.au, and it says company.com.au is not responding.
I've bugged our Microsoft experts to see if they can spot anything, but I thought I'd also bug the splunk community.
↧