All Apps and Add-ons

Setting up the Splunk Add-on for ServiceNow, why are we getting error "The Read Operation Timed Out" when defining the URL and connection parameters?

rgarza
Engager

We are attempting to install and enable the Splunk Add-on for ServiceNow for Splunk. When we attempt to define the URL and connection parameters for our ServiceNow instance, Splunk throws an error that indicates the operation has timed out. We have adjusted the TimeOut from 120 to 3000

I am trying to integrate service with Splunk and I have uploaded the Service Now add-on app in Splunk, and while trying to save the Service Now Add-on Setup, I am getting this error:

Encountered the following error while trying to update: Splunkd daemon is not responding: (u'Error connecting to /servicesNS/nobody/Splunk_TA_snow/apps/local/Splunk_TA_snow/setup: The read operation timed out',) 
Version :

I am using same user name/password in Splunk/service, while configuring the ServiceNow add-on setup in Splunk. I have also tested the setup with the admin password and the error still exists.

rpille_splunk
Splunk Employee
Splunk Employee

Okay, further investigation complete. We hope to fix the underlying issue that causes the setup timeout in the next Splunk platform release. Meanwhile, here are your options:
1. Run this add-on on *nix machines to avoid the issue.
2. Keep trying the workaround: refresh the page and try again. When the machine and/or REST API are very busy, the timeout will happen, but if you catch it at a good moment you might get through. Other users have had success this way.
3. Set up the add-on using service_now.conf instead of using Splunk Web. Don't forget that you need to do this on your search heads as well as on your data collection node if you want to use the push integration. http://docs.splunk.com/Documentation/AddOns/latest/ServiceNow/Setuptheadd-on#Set_up_the_add-on_using...

I hope this helps!

johnoke
Explorer

same issue with Ubuntu 18.04.4 LTS

0 Karma

LewisWheeler
Communicator

Can we have an update on this please? I am encountering the same issue.

0 Karma

srikanth1213
Path Finder

Even we are facing the same issue

0 Karma

LewisWheeler
Communicator

To anyone else reading this, does not work for Windows. I moved to CentOS and works now.

0 Karma

kdanielsobrien
Explorer

Do you know if this now works for Windows? I'm getting the same error when I try too.

0 Karma

rpille_splunk
Splunk Employee
Splunk Employee

Hi rgarza? What version of the Splunk platform are you using, what version of the add-on, and are you on Windows or *nix?

If you are on Windows, there is a known issue with setup timeouts, and the workaround is to refresh the page and try again.

rgarza
Engager

We are currently running the following Setup:

Splunk Enterprise 6.2.1
Splunk add on app 2.8.0
ServiceNow - Geneva
Environment Windows 2012 R2 Standard Edition 64 bit OS

You indicated that there is known issue with the setup and times, Can you provide the details for the work around? We have attempted to modify the conf file to reset the value from 300 to 3000. That did not resolve the error we are reporting. Can you provide explicit instructions on how to crrect this error?

0 Karma

rpille_splunk
Splunk Employee
Splunk Employee

rgarza, I'm working on getting more information for you, but my latest information stated that refreshing and trying again does resolve the issue. I am waiting to hear whether that workaround is only expected to work on Splunk platform version 6.3.0 and later.

Meanwhile, if you have the ability to collect your ServiceNow data on a *nix instance, you could try that to verify that it is indeed this known Windows issue that you are encountering and not some other issue.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...