Alerting

How to resolve error "Upload failed with ERROR : Read Timeout for the log file" when uploading a generated alert log to Splunk?

mengye
New Member

Hi,

I tried to upload the generated alert to Splunk with the function "Upload File" After few mins, it shows "Upload failed with ERROR : Read Timeout for the log file".

It could related with the format of generated alert. But I don't know what is issue with alert log, which is in own format.

The error message is pretty general for ""Upload failed with ERROR : Read Timeout for the log file" " How can I know the exact issue and change the file?

Thank you!

0 Karma

Tdot
Loves-to-Learn

1. Browse to the location of "server.conf" file assuming you've installed Splunk in /opt/splunk and edit it: $ sudo nano /opt/splunk/etc/system/local/server.conf

2. From the "server.conf" file, go to the bottom of the screen and in a new line, press Enter and then add:

[diskUsage]

minFreeSpace = 10

3.  Save the "server.conf" file

4. Restart Splunk Service: $ sudo /opt/splunk/bin/splunk  stop

5. Upload the file.

0 Karma

jchefdeville
Engager

If you are talking about the Fundamentals 1 training, I resolved the issue by editing $SPLUNK_HOME/etc/system/local/server/conf
and adding

[diskUsage]
minFreeSpace = 10

description for this stanza and what it does is in http://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf

,

thomasje
New Member

I got the same error "Upload failed with ERROR : Read Timeout". Please help

0 Karma

Tdot
Loves-to-Learn

1. Browse to the location of "server.conf" file assuming you've installed Splunk in /opt/splunk and edit it: $ sudo nano /opt/splunk/etc/system/local/server.conf

2. From the "server.conf" file, go to the bottom of the screen and in a new line, press Enter and then add:

[diskUsage]

minFreeSpace = 10

3.  Save the "server.conf" file

4. Restart Splunk Service: $ sudo /opt/splunk/bin/splunk  stop

5. Upload the file.

0 Karma
Get Updates on the Splunk Community!

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...

What's New in Splunk Cloud Platform 9.2.2406?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2406 with many ...