Monitoring Splunk

"HttpListener - Socket error from 127.0.0.1 ... Broken pipe" splunkd.log messages since upgrading to Splunk 6.1.5

wrangler2x
Motivator

The full message is:

WARN HttpListener - Socket error from 127.0.0.1 while accessing /servicesNS/-/search/admin/summarization: Broken pipe

It is always the same. I get five of them in a row, a second apart. I see them at 15, 30, 40 and 45 minutes after the hour.

I am on Splunk 6.1.5 build 239630

When splunk is starting up I see these:

12-09-2014 11:43:35.753 -0800 INFO  loader - Limiting REST HTTP server to 2730 sockets
12-09-2014 11:43:35.753 -0800 INFO  loader - Limiting REST HTTP server to 397 threads

$ ulimit -n
8192

I'm wondering what it was doing and what I need to do to stop the errors.

mwong
Splunk Employee
Splunk Employee

Hi,

Please check the ulimit -u , default value is more than 150k. Please change that, it should fix that.

kiril123
Path Finder

are you saying that 150k default value has to be changed? To what value?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...