<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Finding the host for which the REST thread limit reached in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Finding-the-host-for-which-the-REST-thread-limit-reached/m-p/312474#M93552</link>
    <description>&lt;P&gt;In splunkd.log, you can find a log. The host of the splunkd.log  is using up threads limit.&lt;/P&gt;

&lt;P&gt;Here is an example;&lt;BR /&gt;
    02-04-2016 12:11:08.983 -0800 WARN  HttpListener - Can't handle request for $&lt;STRONG&gt;REST_request_here&lt;/STRONG&gt;$, max thread limit for REST HTTP server is 1000, threads already in use is 1001&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 13:36:52 GMT</pubDate>
    <dc:creator>Masa</dc:creator>
    <dc:date>2020-09-29T13:36:52Z</dc:date>
    <item>
      <title>Finding the host for which the REST thread limit reached</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Finding-the-host-for-which-the-REST-thread-limit-reached/m-p/312470#M93548</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I could see the following warning :&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;" Can't handle request max thread limit for REST HTTP server"&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Is there any way that we could know because of which hosts or queries we are getting this warning ?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 17:58:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Finding-the-host-for-which-the-REST-thread-limit-reached/m-p/312470#M93548</guid>
      <dc:creator>kteng2024</dc:creator>
      <dc:date>2017-04-05T17:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Finding the host for which the REST thread limit reached</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Finding-the-host-for-which-the-REST-thread-limit-reached/m-p/312471#M93549</link>
      <description>&lt;P&gt;Do you want to provide a bit more detail as to what exactly you are doing? Who is calling what via REST etc.&lt;BR /&gt;
Without knowing a bit more about your setup, it'll be hard to help, I suspect.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 18:12:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Finding-the-host-for-which-the-REST-thread-limit-reached/m-p/312471#M93549</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-04-05T18:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Finding the host for which the REST thread limit reached</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Finding-the-host-for-which-the-REST-thread-limit-reached/m-p/312472#M93550</link>
      <description>&lt;P&gt;First, I would check the thread limit.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.3/Troubleshooting/HTTPthreadlimitissues"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.3/Troubleshooting/HTTPthreadlimitissues&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Then, the number is high enough, and the issue persists, I would recommend to contact Splunk Support for further investigation.&lt;BR /&gt;
Splunk Support will probably ask to collect diag, ps or top output with thread option, and pstack so that Splunk engineer will be able to look into thread stacks. &lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 23:20:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Finding-the-host-for-which-the-REST-thread-limit-reached/m-p/312472#M93550</guid>
      <dc:creator>Masa</dc:creator>
      <dc:date>2017-04-05T23:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: Finding the host for which the REST thread limit reached</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Finding-the-host-for-which-the-REST-thread-limit-reached/m-p/312473#M93551</link>
      <description>&lt;P&gt;Thank you .. Is there any way that we could know which hosts are responsible for this warning ?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 17:13:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Finding-the-host-for-which-the-REST-thread-limit-reached/m-p/312473#M93551</guid>
      <dc:creator>kteng2024</dc:creator>
      <dc:date>2017-04-06T17:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: Finding the host for which the REST thread limit reached</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Finding-the-host-for-which-the-REST-thread-limit-reached/m-p/312474#M93552</link>
      <description>&lt;P&gt;In splunkd.log, you can find a log. The host of the splunkd.log  is using up threads limit.&lt;/P&gt;

&lt;P&gt;Here is an example;&lt;BR /&gt;
    02-04-2016 12:11:08.983 -0800 WARN  HttpListener - Can't handle request for $&lt;STRONG&gt;REST_request_here&lt;/STRONG&gt;$, max thread limit for REST HTTP server is 1000, threads already in use is 1001&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:36:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Finding-the-host-for-which-the-REST-thread-limit-reached/m-p/312474#M93552</guid>
      <dc:creator>Masa</dc:creator>
      <dc:date>2020-09-29T13:36:52Z</dc:date>
    </item>
  </channel>
</rss>

