Getting Data In

connection aborted error 104 connection reset by peer

logloganathan
Motivator

when i look into the Splunk logs it showing only few logs
other logs are missing with error "connection aborted error 104 connection reset by peer"

Could anyone explain why it occurs?

Tags (1)
0 Karma
1 Solution

logloganathan
Motivator

we need to change the end URL(for getting logs) to fix this issue

View solution in original post

0 Karma

logloganathan
Motivator

we need to change the end URL(for getting logs) to fix this issue

0 Karma

woodcock
Esteemed Legend

What does this mean? What did you actually change?

0 Karma

logloganathan
Motivator

this is actually issue in end URL. we used old Rest URL that why we not getting logs which throws the error.
we modified that with new Rest URL

0 Karma

jlvix1
Communicator

check over your TLS/SSL certs, config and settings on all endpoints.

0 Karma

logloganathan
Motivator

Could anyone please help?

0 Karma

poete
Builder

Hi. Are you truing to have allok into the log files or through a search request. In case it is a search request, can you please rovide it?

0 Karma

logloganathan
Motivator

allok means ?
Could you please explain what is that?
we have written some script to get the logs..its not search query..we are not getting logs into index properly

0 Karma

logloganathan
Motivator

Could anyone please help me in this issue

0 Karma

poete
Builder

So you are using an HEC communication to get the log info in splunk?

0 Karma

logloganathan
Motivator

we are using rest API link to get the log information into the splunk

0 Karma

poete
Builder

So you did follow this?

0 Karma

logloganathan
Motivator

here what step i need to follow?

0 Karma

logloganathan
Motivator

could anyone please help in this issue?

0 Karma

logloganathan
Motivator

Any update from any one?

0 Karma

poete
Builder

Sorry that I wrote too fast. allok => a look. So you try to get the logs in Splunk. How are you trying to do that? Through http?

0 Karma

logloganathan
Motivator

we are getting using http

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...