<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic &amp;quot;HttpListener - Socket error from 127.0.0.1 ...  Broken pipe&amp;quot; splunkd.log messages since upgrading to Splunk 6.1.5 in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/quot-HttpListener-Socket-error-from-127-0-0-1-Broken-pipe-quot/m-p/155348#M1760</link>
    <description>&lt;P&gt;The full message is:&lt;/P&gt;

&lt;P&gt;WARN  HttpListener - Socket error from 127.0.0.1 while accessing /servicesNS/-/search/admin/summarization: Broken pipe&lt;/P&gt;

&lt;P&gt;It is always the same. I get five of them in a row, a second apart. I see them at 15, 30, 40 and 45 minutes after the hour.&lt;/P&gt;

&lt;P&gt;I am on Splunk 6.1.5 build 239630&lt;/P&gt;

&lt;P&gt;When splunk is starting up I see these:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;12-09-2014 11:43:35.753 -0800 INFO  loader - Limiting REST HTTP server to 2730 sockets
12-09-2014 11:43:35.753 -0800 INFO  loader - Limiting REST HTTP server to 397 threads
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;$ ulimit -n&lt;BR /&gt;
8192&lt;/P&gt;

&lt;P&gt;I'm wondering what it was doing and what I need to do to stop the errors.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Dec 2014 00:51:18 GMT</pubDate>
    <dc:creator>wrangler2x</dc:creator>
    <dc:date>2014-12-10T00:51:18Z</dc:date>
    <item>
      <title>"HttpListener - Socket error from 127.0.0.1 ...  Broken pipe" splunkd.log messages since upgrading to Splunk 6.1.5</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/quot-HttpListener-Socket-error-from-127-0-0-1-Broken-pipe-quot/m-p/155348#M1760</link>
      <description>&lt;P&gt;The full message is:&lt;/P&gt;

&lt;P&gt;WARN  HttpListener - Socket error from 127.0.0.1 while accessing /servicesNS/-/search/admin/summarization: Broken pipe&lt;/P&gt;

&lt;P&gt;It is always the same. I get five of them in a row, a second apart. I see them at 15, 30, 40 and 45 minutes after the hour.&lt;/P&gt;

&lt;P&gt;I am on Splunk 6.1.5 build 239630&lt;/P&gt;

&lt;P&gt;When splunk is starting up I see these:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;12-09-2014 11:43:35.753 -0800 INFO  loader - Limiting REST HTTP server to 2730 sockets
12-09-2014 11:43:35.753 -0800 INFO  loader - Limiting REST HTTP server to 397 threads
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;$ ulimit -n&lt;BR /&gt;
8192&lt;/P&gt;

&lt;P&gt;I'm wondering what it was doing and what I need to do to stop the errors.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 00:51:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/quot-HttpListener-Socket-error-from-127-0-0-1-Broken-pipe-quot/m-p/155348#M1760</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2014-12-10T00:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: "HttpListener - Socket error from 127.0.0.1 ...  Broken pipe" splunkd.log messages since upgrading to Splunk 6.1.5</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/quot-HttpListener-Socket-error-from-127-0-0-1-Broken-pipe-quot/m-p/155349#M1761</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;Please check the ulimit -u , default value is more than 150k. Please change that, it should fix that. &lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 01:36:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/quot-HttpListener-Socket-error-from-127-0-0-1-Broken-pipe-quot/m-p/155349#M1761</guid>
      <dc:creator>mwong</dc:creator>
      <dc:date>2015-03-19T01:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: "HttpListener - Socket error from 127.0.0.1 ...  Broken pipe" splunkd.log messages since upgrading to Splunk 6.1.5</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/quot-HttpListener-Socket-error-from-127-0-0-1-Broken-pipe-quot/m-p/155350#M1762</link>
      <description>&lt;P&gt;are you saying that 150k default value has to be changed? To what value?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2017 17:45:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/quot-HttpListener-Socket-error-from-127-0-0-1-Broken-pipe-quot/m-p/155350#M1762</guid>
      <dc:creator>kiril123</dc:creator>
      <dc:date>2017-09-29T17:45:30Z</dc:date>
    </item>
  </channel>
</rss>

