Getting Data In

500 internal server Error and Windows winsock error 10055 (splunkd.log) after upgrading to 5.0.1

Masa
Splunk Employee
Splunk Employee

Windows winsock error 10055 after upgrading to 5.0.1

We have Windows 2k8 servers and 2k3 server for three search heads and two indexers. We upgraded from 4.3.4 to 5.0.1. Then, we started to have issues of accessing to Splunkweb with "500 Internal server error" a few times a week. Then, we realized that we cannot RDP to the server, either. We had to reboot the server.

It seems like there is no issue on the indexers because I could login to them and run searches directly to the indexers.

As far as I know, we haven't added any apps. But, I'm sure there are more scheduled searches were created by users. I'm not sure how to troubleshoot this.

Tags (2)
1 Solution

Masa
Splunk Employee
Splunk Employee

We know v5.0.1 uses more resources. Probably that's the reason you're reaching the limit of Windows Socket buffer.

According to Microsoft Website, the error means;

Winsock Error 10055:
No buffer space available. An operation on a socket could not be performed because the system lacked sufficient buffer space or because a queue was full.

If that's the case, solution would be;

Apply a hotfix from Microsoft
( http://support.microsoft.com/kb/2577795 )

Or,

Change the limit in the registry directly
( http://support.microsoft.com/kb/Q196271 )

So far, we haven't seen the error after applying the hotfix.

You can also find more details regarding this issue in this documentation topic.

View solution in original post

Masa
Splunk Employee
Splunk Employee

We know v5.0.1 uses more resources. Probably that's the reason you're reaching the limit of Windows Socket buffer.

According to Microsoft Website, the error means;

Winsock Error 10055:
No buffer space available. An operation on a socket could not be performed because the system lacked sufficient buffer space or because a queue was full.

If that's the case, solution would be;

Apply a hotfix from Microsoft
( http://support.microsoft.com/kb/2577795 )

Or,

Change the limit in the registry directly
( http://support.microsoft.com/kb/Q196271 )

So far, we haven't seen the error after applying the hotfix.

You can also find more details regarding this issue in this documentation topic.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...