Splunk Enterprise

Why am I getting these socket errors?

tkwaller_2
Communicator

HttpListener - Socket error from while accessing /services/streams/search: Broken pipe?

Here's my ulimit info
ulimit -a
core file size (blocks, -c) 0
data seg size (kbytes, -d) unlimited
scheduling priority (-e) 0
file size (blocks, -f) unlimited
pending signals (-i) 31866
max locked memory (kbytes, -l) 64
max memory size (kbytes, -m) unlimited
open files (-n) 10240
pipe size (512 bytes, -p) 8
POSIX message queues (bytes, -q) 819200
real-time priority (-r) 0
stack size (kbytes, -s) 8192
cpu time (seconds, -t) unlimited
max user processes (-u) 31866
virtual memory (kbytes, -v) unlimited
file locks (-x) unlimited

Please help!

0 Karma

ccl0utier
Splunk Employee
Splunk Employee

I suggest you check the following Splunk answer: https://answers.splunk.com/answers/105292/what-is-the-cause-of-these-socket-errors-reported-in-splun...

I'd then check your splunkd.log logs for anything mentioning a limit being hit or something that might help explain that behaviour (probably for the HTTPListener component).

As a last resort, you might want to do a network trace (Wireshark, NetMon, etc...) with or without the help of your network team. That should help you see what is happening from the network side and might help direct where to look for the issue's root cause next.

0 Karma

hettervik
Builder

Hi! Did you ever find out why you were getting the broken pipe warning? I've seem to have encountered the same problem. One observation from my side is that I'm low on free RAM on the machine, but I don't know if this is related or not.

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...