<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why the error &amp;quot;Socket error from [Search Head IP] while accessing /services/streams/search: broken pipe&amp;quot;? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/625581#M14936</link>
    <description>&lt;P&gt;Did any of you ever fixed this issue? If so, how?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Sun, 01 Jan 2023 08:08:42 GMT</pubDate>
    <dc:creator>tfellinger</dc:creator>
    <dc:date>2023-01-01T08:08:42Z</dc:date>
    <item>
      <title>What is this error "Socket error from [Search Head IP] while accessing /services/streams/search: broken pipe"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/617577#M14249</link>
      <description>&lt;P&gt;I have recently run into an issue with multiple "WARN HttpListener [HttpDedicatedIoThread:0]  Socket error from [Search Head IP] while accessing /services/streams/search: broken pipe" for each Indexer in the Index cluster.&lt;/P&gt;
&lt;P&gt;There is a SH cluster, and a standalone SH.  The standalone houses an app that does heavy backend searching.   And the majority of the errors are from the standalone.  When looking at the "I/O Operations per second" and "Storage I/O Saturation (cold/hot/opt)" from the Monitoring Console all instances are below 1%.&lt;/P&gt;
&lt;P&gt;I am not sure which settings to adjust to fix this error.  Would adjusting the maxSockets and/or maxThreads in the server.conf help?  Currently they are both set to default.  Or should I be looking at values in limits.conf?&lt;/P&gt;
&lt;P&gt;This is happening on version 9.0.1.  Any suggestions to help solve this would be much appreciated.  Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 00:34:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/617577#M14249</guid>
      <dc:creator>jencot01</dc:creator>
      <dc:date>2022-12-02T00:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why the error "Socket error from [Search Head IP] while accessing /services/streams/search: broken pipe"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/617880#M14282</link>
      <description>&lt;P&gt;To add to the above, I have also found this error in splunkd.log on the indexers:&lt;/P&gt;&lt;P&gt;ERROR SearchProcessRunner&amp;nbsp; PreforkedSearchesManager-0&amp;nbsp; &amp;nbsp;- preforked process = 0/253717&amp;nbsp; hung up&lt;/P&gt;&lt;P&gt;This error aligns with the "broken pipe" error on my post above.&amp;nbsp; There are no skipped searches.&lt;/P&gt;&lt;P&gt;I'm at a loss to what I steps I should take next to troubleshoot this issue.&amp;nbsp; &amp;nbsp;Again, any help/suggestions would be appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 15:31:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/617880#M14282</guid>
      <dc:creator>jencot01</dc:creator>
      <dc:date>2022-10-20T15:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why the error "Socket error from [Search Head IP] while accessing /services/streams/search: broken pipe"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/622925#M14669</link>
      <description>&lt;P&gt;We recently upgraded our deployment (IDX Cluster + SH Cluster) from 8.2.6 to 9.0.1&lt;/P&gt;&lt;P&gt;Since the upgrade, we see a huge number of warnings for :&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;WARN HttpListener [8466 HttpDedicatedIoThread-7] - Socket error from &amp;lt;ip:port&amp;gt; while accessing &amp;lt;URI&amp;gt;: Broken pipe&lt;/LI-CODE&gt;&lt;P&gt;Along with this, there are huge number of errors for Captain Disconnected, "This member has marked the connection to the search head captain as down", timeouts, and skipped searches.&lt;/P&gt;&lt;P&gt;These errors/warnings typically occur during peak loads.&lt;/P&gt;&lt;P&gt;As such we found that THP was enabled on few of SH Cluster members. ulimits were set to Splunk recommended values, but we are in the process of increasing them in our prod env.&lt;/P&gt;&lt;P&gt;Further troubleshooting pending, Will get back with updates.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 23:50:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/622925#M14669</guid>
      <dc:creator>anirban_td</dc:creator>
      <dc:date>2022-12-01T23:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why the error "Socket error from [Search Head IP] while accessing /services/streams/search: broken pipe"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/625581#M14936</link>
      <description>&lt;P&gt;Did any of you ever fixed this issue? If so, how?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jan 2023 08:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/625581#M14936</guid>
      <dc:creator>tfellinger</dc:creator>
      <dc:date>2023-01-01T08:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why the error "Socket error from [Search Head IP] while accessing /services/streams/search: broken pipe"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/625638#M14945</link>
      <description>&lt;P&gt;I was never able to fix the issue.&amp;nbsp; Still trying to figure it out.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2023 18:35:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/625638#M14945</guid>
      <dc:creator>jlc00</dc:creator>
      <dc:date>2023-01-02T18:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why the error "Socket error from [Search Head IP] while accessing /services/streams/search: broken pipe"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/651413#M16867</link>
      <description>&lt;P&gt;Same happened to our Infrastructure after Upgrading from 8.2.9 -&amp;gt; 9.0.5. Has anybody figured out whats causing this messages and what the impact is?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;07-21&lt;/SPAN&gt;-&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;07:42:16.414&lt;/SPAN&gt;&lt;SPAN&gt; +&lt;/SPAN&gt;&lt;SPAN class=""&gt;0200&lt;/SPAN&gt; &lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class=""&gt;SearchProcessRunner&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;24412&lt;/SPAN&gt; &lt;SPAN class=""&gt;PreforkedSearchesManager-0&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;preforked&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;process&lt;/SPAN&gt;=063487&lt;/SPAN&gt; &lt;SPAN class=""&gt;hung&lt;/SPAN&gt; &lt;SPAN class=""&gt;up&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 06:08:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/651413#M16867</guid>
      <dc:creator>mika703</dc:creator>
      <dc:date>2023-07-21T06:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why the error "Socket error from [Search Head IP] while accessing /services/streams/search: broken pipe"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/661193#M17663</link>
      <description>&lt;P&gt;Seeing the same after an upgrade from v8 to v9.0.6.&lt;BR /&gt;I'm suspecting something went wrong during the upgrade but don't have any solid evidence yet.&amp;nbsp;&lt;BR /&gt;Did anyone manage to get to the bottom of this ?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 13:49:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/661193#M17663</guid>
      <dc:creator>Gregster66</dc:creator>
      <dc:date>2023-10-18T13:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Why the error "Socket error from [Search Head IP] while accessing /services/streams/search: broken pipe"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/661218#M17664</link>
      <description>&lt;P&gt;We are still having these ERROR Messages since the upgrade. Never found some evidence or root cause &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 15:20:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-this-error-quot-Socket-error-from-Search-Head-IP-while/m-p/661218#M17664</guid>
      <dc:creator>mika703</dc:creator>
      <dc:date>2023-10-18T15:20:50Z</dc:date>
    </item>
  </channel>
</rss>

