Monitoring Splunk

"HttpListener - Socket error from ... Broken pipe" splunkd.log messages since upgrading to Splunk 6.1.5


The full message is:

WARN HttpListener - Socket error from while accessing /servicesNS/-/search/admin/summarization: Broken pipe

It is always the same. I get five of them in a row, a second apart. I see them at 15, 30, 40 and 45 minutes after the hour.

I am on Splunk 6.1.5 build 239630

When splunk is starting up I see these:

12-09-2014 11:43:35.753 -0800 INFO  loader - Limiting REST HTTP server to 2730 sockets
12-09-2014 11:43:35.753 -0800 INFO  loader - Limiting REST HTTP server to 397 threads

$ ulimit -n

I'm wondering what it was doing and what I need to do to stop the errors.

Splunk Employee
Splunk Employee


Please check the ulimit -u , default value is more than 150k. Please change that, it should fix that.

Path Finder

are you saying that 150k default value has to be changed? To what value?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...