Getting Data In

Max connection count to API?

twinspop
Influencer

I wrote a simple, REST-based proxy to query Splunk's REST API from SiteScope. The proxy manages job creation, tracking etc so that SiteScope can simply issue a GET on a URL and get easily parsable XML in return. I have 25 or so monitors that use it, and they run once per minute.

Very often the proxy gets a 503 server unavailable message from Splunk. Apparently I'm hitting a limit on the API interface? Is there a switch to adjust this?

v4.1.5

EDIT2:

My $SPLUNK_HOME/etc/system/local/authorize.conf file:

[default]
run_web_script_fields = enabled
run_web_script_surrounding_events = enabled

[role_user]
srchJobsQuota = 16

The user I am hitting the API with is in the "user" role.

Tags (3)
0 Karma

tradel
New Member

Try this in server.conf:

[managementServer]
maxBackLog = 100
requestQueueSize = 100
threadPoolSize = 100
0 Karma

twinspop
Influencer

More research from the SiteScope end: When I get the error there are at most 2 or 3 other searches running. Doesn't seem like too many.

0 Karma

twinspop
Influencer

Nope. Still getting the 503s. 😞

0 Karma

twinspop
Influencer
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...