Monitoring Splunk

What is causing AwsSDK error?

vik
Explorer

Hi Team, 

 

We are noticing suddenly started noticing these errors in splunkd log. Any idea what could cause these ? We didnt make any changes to the splunkforwarder app. 

 

06-01-2023 20:40:19.027 -0700 ERROR AwsSDK [4839 ExecProcessor] - CurlHttpClient Curl returned error code 28 - Timeout was reached
06-01-2023 20:40:19.027 -0700 ERROR AwsSDK [4839 ExecProcessor] - EC2MetadataClient Http request to retrieve credentials failed
06-01-2023 20:40:20.029 -0700 ERROR AwsSDK [4839 ExecProcessor] - CurlHttpClient Curl returned error code 28 - Timeout was reached
06-01-2023 20:40:20.029 -0700 ERROR AwsSDK [4839 ExecProcessor] - EC2MetadataClient Http request to retrieve credentials failed
06-01-2023 20:40:20.029 -0700 ERROR AwsSDK [4839 ExecProcessor] - EC2MetadataClient Can not retrive resource from http://169.254.169.254/latest/meta-data/placement/availability-zone

Labels (4)
0 Karma

hahabuknow
Engager

Hi @vik  , I'm encountering the same issue. Did you resolve it?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
As it access local endpoint, could it be that your server have increased load so much that timeout has reached?
0 Karma

vik
Explorer

The IP seems to be a generic IP and it does not seem to be a local endpoint. I could see other posts on the internet have the same IP.

It seems like something is the system is trying to invoke this endpoint. But I do not understand what is triggering this endpoint.  

0 Karma

isoutamo
SplunkTrust
SplunkTrust

This IP is for AWS:s internal local endpoint to collect AWS instance information using REST API like calling it with curl. It's same on all AWS EC2 instances and you could get e.g. region, zone, instance type etc. from it.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...