Monitoring Splunk

Why is the Http Even tCollector LogbackAppender is hanging on connection request?

davemforeflight
Engager

Logs look like:

o.a.http.impl.nio.client.MainClientExec : [exchange: 2] start execution
2018-06-20 16:00:04.014 DEBUG 44700 --- [ main] o.a.h.client.protocol.RequestAddCookies : CookieSpec selected: standard
2018-06-20 16:00:04.014 DEBUG 44700 --- [ main] o.a.h.client.protocol.RequestAuthCache : Auth cache not set in the context
2018-06-20 16:00:04.015 DEBUG 44700 --- [ main] o.a.h.i.n.c.InternalHttpAsyncClient : [exchange: 2] Request connection for {s}->https://input-prd-p-XXXXX.cloud.splunk.com:8088

I have disableCertificateValidation set to true (and can submit json logs via curl and postman). I've also tried adding the clound.splunk.com cert to a trustStore.

Any ideas?

Tags (2)
0 Karma
1 Solution

davemforeflight
Engager

SOLVED:

SpringBoot environment with and unreachable Spring Configuration Server. The attempted connection to the config server was blocking the entire app boot process just after the log stack started. So looked like the log stack was hanging, but was really the spring context not starting.

Derp.

View solution in original post

0 Karma

davemforeflight
Engager

SOLVED:

SpringBoot environment with and unreachable Spring Configuration Server. The attempted connection to the config server was blocking the entire app boot process just after the log stack started. So looked like the log stack was hanging, but was really the spring context not starting.

Derp.

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2023 Splunk Career Impact Report

We’ve been shouting it from the rooftops! The findings from the 2023 Splunk Career Impact Report showing that ...

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...