<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What could cause splunkd.log to be flooded with &amp;quot;ERROR HttpClientRequest - HTTP client error=Read Timeout while connecting to server&amp;quot;? in Security</title>
    <link>https://community.splunk.com/t5/Security/What-could-cause-splunkd-log-to-be-flooded-with-quot-ERROR/m-p/339558#M8641</link>
    <description>&lt;P&gt;How does the system resource usage on your search heads look?  And is there a large number of concurrent searches?  You may want to take a look at the "Search Activity: Instance" dashboard in the Monitoring Console to see if there are searches running using a large amount of memory.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jan 2018 20:45:36 GMT</pubDate>
    <dc:creator>traxxasbreaker</dc:creator>
    <dc:date>2018-01-30T20:45:36Z</dc:date>
    <item>
      <title>What could cause splunkd.log to be flooded with "ERROR HttpClientRequest - HTTP client error=Read Timeout while connecting to server"?</title>
      <link>https://community.splunk.com/t5/Security/What-could-cause-splunkd-log-to-be-flooded-with-quot-ERROR/m-p/339557#M8640</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I recently joined a project at a place with an ES Search head and a few ad-hoc ones. Apparently, there has been a new issue that started a few days before I got here. The ES SH (others are fine) will go unresponsive for web browsing until it is restarted. The web daemon and splunkd are still running. Alerts and searches are still running.&lt;/P&gt;

&lt;P&gt;Splunkd is just &lt;EM&gt;bombarded&lt;/EM&gt; with &lt;CODE&gt;"ERROR HttpClientRequest - HTTP client error=Read Timeout while connecting to server"&lt;/CODE&gt; messages and pretty much nothing else. I'm trying to help them figure out what the issue is, but I've never seen something like this happen.&lt;/P&gt;

&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 16:57:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-could-cause-splunkd-log-to-be-flooded-with-quot-ERROR/m-p/339557#M8640</guid>
      <dc:creator>jadamsplunk</dc:creator>
      <dc:date>2018-01-30T16:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: What could cause splunkd.log to be flooded with "ERROR HttpClientRequest - HTTP client error=Read Timeout while connecting to server"?</title>
      <link>https://community.splunk.com/t5/Security/What-could-cause-splunkd-log-to-be-flooded-with-quot-ERROR/m-p/339558#M8641</link>
      <description>&lt;P&gt;How does the system resource usage on your search heads look?  And is there a large number of concurrent searches?  You may want to take a look at the "Search Activity: Instance" dashboard in the Monitoring Console to see if there are searches running using a large amount of memory.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 20:45:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-could-cause-splunkd-log-to-be-flooded-with-quot-ERROR/m-p/339558#M8641</guid>
      <dc:creator>traxxasbreaker</dc:creator>
      <dc:date>2018-01-30T20:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: What could cause splunkd.log to be flooded with "ERROR HttpClientRequest - HTTP client error=Read Timeout while connecting to server"?</title>
      <link>https://community.splunk.com/t5/Security/What-could-cause-splunkd-log-to-be-flooded-with-quot-ERROR/m-p/339559#M8642</link>
      <description>&lt;P&gt;That was my first thought as well, but I can't access anything on the SH when it's like that. Looking at the charts historically for when it happens, though, I don't see any spikes.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 20:47:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-could-cause-splunkd-log-to-be-flooded-with-quot-ERROR/m-p/339559#M8642</guid>
      <dc:creator>jadamsplunk</dc:creator>
      <dc:date>2018-01-30T20:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: What could cause splunkd.log to be flooded with "ERROR HttpClientRequest - HTTP client error=Read Timeout while connecting to server"?</title>
      <link>https://community.splunk.com/t5/Security/What-could-cause-splunkd-log-to-be-flooded-with-quot-ERROR/m-p/339560#M8643</link>
      <description>&lt;P&gt;if the ES search head forwards its data to indexer layer, you supposed to be able to query its status through another search head: index = _internal host=ES_Searhc_Head&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:52:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-could-cause-splunkd-log-to-be-flooded-with-quot-ERROR/m-p/339560#M8643</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2020-09-29T17:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: What could cause splunkd.log to be flooded with "ERROR HttpClientRequest - HTTP client error=Read Timeout while connecting to server"?</title>
      <link>https://community.splunk.com/t5/Security/What-could-cause-splunkd-log-to-be-flooded-with-quot-ERROR/m-p/339561#M8644</link>
      <description>&lt;P&gt;Hi did you find out what caused this error?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2018 16:53:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-could-cause-splunkd-log-to-be-flooded-with-quot-ERROR/m-p/339561#M8644</guid>
      <dc:creator>mrtolu6</dc:creator>
      <dc:date>2018-08-20T16:53:34Z</dc:date>
    </item>
  </channel>
</rss>

