All Apps and Add-ons

Has anyone encountered this error when sending logs to 3rd party syslog destination using Splunk App for CEF?

miguelsollegue
Loves-to-Learn Lots

Has anyone encountered this error when sending logs to 3rd party syslog destination using Splunk App for CEF

I'm getting the following error.

11-03-2022 11:23:25.904 ERROR ChunkedExternProcessor [32136 ChunkedExternProcessorStderrLogger] - stderr: splunk.SplunkdConnectionException: Splunkd daemon is not responding: ('Error connecting to /services/data/inputs/all: The read operation timed out',)
11-03-2022 11:23:25.904 ERROR ChunkedExternProcessor [15688 searchOrchestrator] - Error in 'cefout' command: Splunkd daemon is not responding: ('Error connecting to /services/data/inputs/all: The read operation timed out',)
11-03-2022 11:23:25.911 ERROR SearchPhaseGenerator [15688 searchOrchestrator] - Fallback to two phase search failed:Error in 'cefout' command: Splunkd daemon is not responding: ('Error connecting to /services/data/inputs/all: The read operation timed out',)
11-03-2022 11:23:25.913 ERROR SearchStatusEnforcer [15688 searchOrchestrator] - sid:scheduler__userid_c3BsdW5rX2FwcF9jZWY__RMD53bb25367b408a898_at_1667434800_56257_BED74D95-D037-415C-8C9C-81F3D2FEEBAB Error in 'cefout' command: Splunkd daemon is not responding: ('Error connecting to /services/data/inputs/all: The read operation timed out',)
11-03-2022 11:23:25.913 INFO SearchStatusEnforcer [15688 searchOrchestrator] - State changed to FAILED due to: Error in 'cefout' command: Splunkd daemon is not responding: ('Error connecting to /services/data/inputs/all: The read operation timed out',)

Labels (3)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...