<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to fix this Splunk Error:Connection closed by peer? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-fix-this-Splunk-Error-Connection-closed-by-peer/m-p/609571#M13645</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;I have 1 search head and 3 indexes with a index cluster, it worked fine until yesterday, today I can't search event, then I found this event from splunkd.log&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;08-16&lt;/SPAN&gt;-2022&lt;/SPAN&gt; &lt;SPAN class=""&gt;13:23:10.727&lt;/SPAN&gt;&lt;SPAN&gt; +&lt;/SPAN&gt;&lt;SPAN class=""&gt;0800&lt;/SPAN&gt; &lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class=""&gt;HttpListener&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;175497&lt;/SPAN&gt; &lt;SPAN class=""&gt;TcpChannelThread&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Exception&lt;/SPAN&gt; &lt;SPAN class=""&gt;while&lt;/SPAN&gt; &lt;SPAN class=""&gt;processing&lt;/SPAN&gt; &lt;SPAN class=""&gt;request&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.20.5.10:38210&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;/services/streams/search&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;SPAN class=""&gt;sh_sid=rt_scheduler__admin_U0EtQWNjZXNzUHJvdGVjdGlvbg__RMD53730174ad49bc45c_at_1660627323_2982:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Connection&lt;/SPAN&gt; &lt;SPAN class=""&gt;closed&lt;/SPAN&gt; &lt;SPAN class=""&gt;by&lt;/SPAN&gt; &lt;SPAN class=""&gt;peer&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;10.20.5.10 is search head server,&lt;/P&gt;
&lt;P&gt;What should I do?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 16 Aug 2022 13:06:56 GMT</pubDate>
    <dc:creator>zhenqi</dc:creator>
    <dc:date>2022-08-16T13:06:56Z</dc:date>
    <item>
      <title>How to fix this Splunk Error:Connection closed by peer?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-fix-this-Splunk-Error-Connection-closed-by-peer/m-p/609571#M13645</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;I have 1 search head and 3 indexes with a index cluster, it worked fine until yesterday, today I can't search event, then I found this event from splunkd.log&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;08-16&lt;/SPAN&gt;-2022&lt;/SPAN&gt; &lt;SPAN class=""&gt;13:23:10.727&lt;/SPAN&gt;&lt;SPAN&gt; +&lt;/SPAN&gt;&lt;SPAN class=""&gt;0800&lt;/SPAN&gt; &lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class=""&gt;HttpListener&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;175497&lt;/SPAN&gt; &lt;SPAN class=""&gt;TcpChannelThread&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Exception&lt;/SPAN&gt; &lt;SPAN class=""&gt;while&lt;/SPAN&gt; &lt;SPAN class=""&gt;processing&lt;/SPAN&gt; &lt;SPAN class=""&gt;request&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.20.5.10:38210&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;/services/streams/search&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;SPAN class=""&gt;sh_sid=rt_scheduler__admin_U0EtQWNjZXNzUHJvdGVjdGlvbg__RMD53730174ad49bc45c_at_1660627323_2982:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Connection&lt;/SPAN&gt; &lt;SPAN class=""&gt;closed&lt;/SPAN&gt; &lt;SPAN class=""&gt;by&lt;/SPAN&gt; &lt;SPAN class=""&gt;peer&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;10.20.5.10 is search head server,&lt;/P&gt;
&lt;P&gt;What should I do?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 13:06:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-fix-this-Splunk-Error-Connection-closed-by-peer/m-p/609571#M13645</guid>
      <dc:creator>zhenqi</dc:creator>
      <dc:date>2022-08-16T13:06:56Z</dc:date>
    </item>
  </channel>
</rss>

