Splunk Search

How to resolve error "This XML file does not appear to have any style information associated with it."

sh254087
Communicator

Getting the error "This XML file does not appear to have any style information associated with it." while trying to export search result.

Search result export error.png

Getting this error within dashboards as well from search(.../search/search) page. 

This is stopping our ability to export/download search results in all available formats(csv/xml/json).

Any possible solutions?

Splunk Enterprise version 9.0.0.1

Labels (1)
Tags (2)
0 Karma

gurlest
Path Finder

We are also having this same error after our upgrade from v8.2.7.1 to v9.0.3.

We are at a loss as to what happened.

Did you guys ever figure it out @sh254087 @splunkadmin5678 ?

0 Karma

gurlest
Path Finder

We were able to find a temp fix...

$SPLUNK_HOME/etc/splunk-launch.conf has a setting PYTHONHTTPSVERIFY that allows for some additional security when setting it to 1 (part of the TLS security fixes from June 2022).

Setting it to 0 (using the default value from $SPLUNK_HOME/etc/splunk-launch.conf.default) causes the 'service unavailble' issues to go away when exporting.

However, this is not the "FIX" for the issue... just a temp fix for your users while you (we?) try to figure out what the real issue is with the self-signed cert validation errors (the 'real' issue) in the logs.

sh254087
Communicator
This is right. We also have applied the same as a temporary fix. As a result - 1. The XML issue will be resolved. 2. There will be an error/warning message showing up at the startup, related to PYTHONHTTPSVERIFY having set to 0 (where the expected value is 1). We can, perhaps, only ignore this for now!
Tags (1)
0 Karma

splunkadmin5678
Observer

Did this issue got resolved for you @sh254087, If yes can you help me on this

0 Karma

sh254087
Communicator

I'm sorry I missed your message. If you're still looking out for a workaround, please refer gurlest's response

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@sh254087 - The error message says "Service Unavailable", meaning you may have some disconnects with Splunk services.

If this is happening regularly you may contact Splunk support.

 

I hope this helps!!! Upvote/karma the post if it does!!

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...