<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Read error when exporting to CSV file in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/555104#M157558</link>
    <description>&lt;P&gt;This worked. Thank you.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jun 2021 14:30:17 GMT</pubDate>
    <dc:creator>Bhupal</dc:creator>
    <dc:date>2021-06-09T14:30:17Z</dc:date>
    <item>
      <title>Read error when exporting to CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/540412#M152885</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;I hope this is the correct board for this question, but I am having an issue when I try to export a search to CSV from a search. I keep getting the following error when trying to run the export. Has anyone seen this and how to resolve it? I am using version 8.1.2 FWIW.&lt;/P&gt;&lt;PRE&gt;Unrecoverable error in the server.
Traceback (most recent call last):
  File "C:\Program Files\Splunk\Python-3.7\lib\site-packages\cherrypy\_cpwsgi.py", line 184, in trap
    return func(*args, **kwargs)
  File "C:\Program Files\Splunk\Python-3.7\lib\site-packages\cherrypy\_cpwsgi.py", line 277, in __next__
    return next(self.iter_response)
  File "C:\Program Files\Splunk\Python-3.7\lib\site-packages\cherrypy\lib\encoding.py", line 99, in encoder
    for chunk in body:
  File "C:\Program Files\Splunk\Python-3.7\lib\site-packages\splunk\rest\__init__.py", line 698, in readall
    data = response.read(blocksize)
  File "C:\Program Files\Splunk\Python-3.7\lib\http\client.py", line 457, in read
    n = self.readinto(b)
  File "C:\Program Files\Splunk\Python-3.7\lib\http\client.py", line 501, in readinto
    n = self.fp.readinto(b)
  File "C:\Program Files\Splunk\Python-3.7\lib\socket.py", line 589, in readinto
    return self._sock.recv_into(b)
  File "C:\Program Files\Splunk\Python-3.7\lib\ssl.py", line 1071, in recv_into
    return self.read(nbytes, buffer)
  File "C:\Program Files\Splunk\Python-3.7\lib\ssl.py", line 929, in read
    return self._sslobj.read(len, buffer)
socket.timeout: The read operation timed out&lt;BR /&gt;&lt;BR /&gt;THanks!&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 15:58:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/540412#M152885</guid>
      <dc:creator>deca2499</dc:creator>
      <dc:date>2021-02-24T15:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Read error when exporting to CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/541236#M153235</link>
      <description>&lt;P&gt;Has anyone seen this in any way? We are running the free version of Splunk and it seems like whatever time range I choose, I get the same error.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 15:54:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/541236#M153235</guid>
      <dc:creator>deca2499</dc:creator>
      <dc:date>2021-02-24T15:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Read error when exporting to CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/541241#M153237</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230458"&gt;@deca2499&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;How big is your result? Do you get the same error even the result is a few small events?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 16:38:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/541241#M153237</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-24T16:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Read error when exporting to CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/541265#M153243</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I was just able to get the export done with 14k results, but when I bumped it up to 24 hours with 330k results, it failed and gave me that error.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 20:04:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/541265#M153243</guid>
      <dc:creator>deca2499</dc:creator>
      <dc:date>2021-02-24T20:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Read error when exporting to CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/553382#M157120</link>
      <description>&lt;P&gt;Hi Deca,&lt;/P&gt;&lt;P&gt;How long does the search for 14k result take&amp;nbsp; and how long does that for 24 hrs take ?&amp;nbsp; When you export report to csv from UI, you have this message on the lower part of the dialogue box&amp;nbsp; "&lt;STRONG&gt;Your search will rerun if the number of results is higher than 1,000".&lt;/STRONG&gt; So my guess is that the 24 hours is taking to much time to run- beyond the timeout setting.&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 17:52:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/553382#M157120</guid>
      <dc:creator>osunjio</dc:creator>
      <dc:date>2021-05-27T17:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Read error when exporting to CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/553547#M157161</link>
      <description>&lt;P&gt;We just upgraded to 8.2 and seeing this error when trying to export 300k+ results to CSV.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 16:24:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/553547#M157161</guid>
      <dc:creator>Bhupal</dc:creator>
      <dc:date>2021-05-28T16:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Read error when exporting to CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/555080#M157550</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230458"&gt;@deca2499&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran into this same problem just this morning. I've since figured out how to resolve the issue:&lt;/P&gt;&lt;P&gt;Update the following setting in web.conf on your search head:&lt;/P&gt;&lt;PRE&gt;splunkdConnectionTimeout&lt;/PRE&gt;&lt;P&gt;I set mine to 180, and was finally able to export large result sets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 12:47:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/555080#M157550</guid>
      <dc:creator>linuxchuck</dc:creator>
      <dc:date>2021-06-09T12:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: Read error when exporting to CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/555104#M157558</link>
      <description>&lt;P&gt;This worked. Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 14:30:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/555104#M157558</guid>
      <dc:creator>Bhupal</dc:creator>
      <dc:date>2021-06-09T14:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Read error when exporting to CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/572054#M199352</link>
      <description>&lt;P&gt;I know I'm chiming in late on this one, but when I change splunkdConnection to 180 (./var/run/splunk/merged/web.conf) it resets back to 30 after restarting splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that the correct web.conf?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 17:09:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/572054#M199352</guid>
      <dc:creator>BrendanCO</dc:creator>
      <dc:date>2021-10-22T17:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: Read error when exporting to CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/572180#M199422</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/169533"&gt;@BrendanCO&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Correct web.conf is at $SPLUNK_HOME/etc/system/local/web.conf&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 03:38:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Read-error-when-exporting-to-CSV-file/m-p/572180#M199422</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-10-25T03:38:02Z</dc:date>
    </item>
  </channel>
</rss>

