Getting Data In

Tutorial data upload error

becksyboy
Communicator

Hi,

I'm fairly new to Splunk and currently undergoing some training. Within my home lab I have a Splunk instance installed and am trying to upload the tutorial data. When i select the .zip file it says "uploading file" and is at 100%. After 10 mins i get an upload Error stating there was a read timeout?

Any ideas why i can't upload the .zip file?

thanks

splunky14
New Member

The only way I solved this is to create a VM. In that VM i created a separate partition and installed Splunk to that (not to C:) doing this I had no upload errors, didn't have to change any specs with server settings, and had no disk space errors.

0 Karma

splunky14
New Member

I too have the same issue. I tried all of the suggestions, but cannot get the tutorial data to load. I always receive the same Upload failed with Error: Read Timeout

0 Karma

louisba
New Member

Re-install Splunk and try to upload the zip file again. Your free license may have expired.

0 Karma

lstewart_splunk
Splunk Employee
Splunk Employee

If the system hangs when you try to upload the file, try the following.

  1. DO NOT unzip the file.
  2. Stop the upload.
  3. Go to Settings > Server settings > General settings.
  4. In the Index settings section, change the value of the parameter Pause indexing if free disk space (in MB) falls below. Change the value to approx. 200 MB lower than the current value. For example, if the setting is 5000, change it to 4800.
  5. Try the upload again.

teanae94577
Explorer

@istewart[splunk] Could you explain why that worked? I want to understand it better.

0 Karma

bandit
Motivator

Splunk defaults to requiring 5GB or 5000MB of free disk space or it will stop functioning properly. Possibly you don't have much disk space free on the file system where Splunk is installed? If this is a testing/sandbox system, I would see no problem with setting the value as low as 100MB free.

0 Karma

louisba
New Member

I am having the same issue uploading the tutorialdata zip file into Splunk. I am using Windows 8.1. I am also new to Splunk and needs the data to practice so I can move to the next level.
Is there a solution? I followed exactly the documentation. Any assistance would be greatly appreciated.

Thank you in advance!

0 Karma

lstewart_splunk
Splunk Employee
Splunk Employee

louisba, see my answer below.

0 Karma

louisba
New Member

I just tried as explained and still got the same error message: "Upload failed with ERROR: Read Timeout." There was a previous warning though as soon as I chose the file stating: "Preview is not supported by this archive file, but it can still be indexed".
Thank you for trying! It seems to be a known issue.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

In order for the tutorial data to work, you should not unzip the file.

What version of Splunk, and what operating system and browser are you using? We have tested the tutorial on multiple platforms, and we did find a file upload defect on Windows 7. We have filed that with the dev team to fix.

sirimuvva
New Member

Hi Chris,

Can you tel me if the Windows 7 defect has been fixed for uploading the data.

I am facing issue while uploading the input data and could see error as "Cannot connect to proxy.', error(10061, 'No connection could be made because the target machine actively refused it')) "

0 Karma

lstewart_splunk
Splunk Employee
Splunk Employee

sirimuvva
The defect is still open. Did you try the workaround mentioned above, in which you change the Settings?

0 Karma

sirimuvva
New Member

Istewart,

Yea I tried with the settings mentioned above. But issue is not resolved. Can you please tell me the reason for this error

"Cannot connect to proxy.', error(10061, 'No connection could be made because the target machine actively refused it')) "

0 Karma

Kamalam1993
New Member

Hi Chris,
I am facing "Upload failed with ERROR : Read Timeout", while uploading the tutorial data. I have tried to install the unzipped file, but it is throwing the same error message. I am using chrome and OS is windows 7. I have tried to change the pause indexing to 4800 too. Is there any upload defect on Windows 7?

0 Karma

lstewart_splunk
Splunk Employee
Splunk Employee

@kamalam1993 - when you changed the pause indexing threshold to 4800, did you then try to upload the unzipped files? You definitely don't want to do that. You want to upload the zipped files.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Yes, the defect is still open. As a workaround, I suggest using a free Splunk Cloud trial to go through the tutorial.

0 Karma

becksyboy
Communicator

Hi Chris,

I'm running my Splunk instance on a Windows 12 R2 server running within VM Ware workstation 12. I have the same error within Internet explorer and Chrome. I have tried uploading the tutorial data when copied locally within the Win12 instance or from a share folder located on my Windows 10 PC running as the Host (where VM workstation is running from).

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Thanks for the additional information. I have added it to the existing bug report (SPL-109362).

0 Karma

becksyboy
Communicator

Hi Chris, forgot to add the Splunk version I'm running is 6.3.

I created a CentOS-7 Vm instance within VM Workstation 12, and have managed to upload the tutorial data with no issues.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Thanks for confirming that this is the Windows bug again, and I am glad you were able to upload the data and proceed on Linux.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...