Splunk Enterprise

HTTP client error=Read Timeout while accessing server=http://127.0.0.1:8065 - Splunk Add-on Builder

edoardo_vicendo
Contributor

Hello,

I am adding an Alert Action with Splunk Add-on Builder, but when I click “save” it basically goes in timeout.

 

edoardo_vicendo_0-1705422916160.png

 

01-16-2024 17:01:31.340 +0100 ERROR HttpClientRequest [24831 TcpChannelThread] - HTTP client error=Read Timeout while accessing server=http://127.0.0.1:8065 for request=http://127.0.0.1:8065/en-US/custom/splunk_app_addon-builder/app_edit_modularalert/add_modular_alert.

 

In the meanwhile if I open a new tab on the browser, whichever page I request falls in timeout as well.

 

edoardo_vicendo_1-1705422953178.png

 

01-16-2024 17:02:18.114 +0100 ERROR HttpClientRequest [7954 TcpChannelThread] - HTTP client error=Read Timeout while accessing server=http://127.0.0.1:8065 for request=http://127.0.0.1:8065/en-US.

 

Looking into the /opt/splunk/etc/apps folder it seems my app stuck in TA-splunk-myapp_temp_output folder meanwhile is saving.

splunk@SearchHead:~/etc/apps > ls -latr
drwxrwxrwx  10 splunk splunk     4096 Jan 15 16:02 TA-splunk-myapp
…
drwxrwxrwx   3 splunk splunk     4096 Jan 16 16:53 TA-splunk-myapp_temp_output

 

I also tried to:

  • cancel the TA-splunk-myapp_temp_output folder, restart Splunk and try again saving.
  • increase performance from 16CPU/32GB to 32CPU/64GB

but I have the same issue.

It seems that the timeout comes from the “appserver” that runs on port 8065.

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Webconf

 

appServerPorts = <positive integer>[, <positive integer>, <positive integer> ...]

* Port number(s) for the python-based application server to listen on.

  This port is bound only on the loopback interface -- it is not

  exposed to the network at large.

* Generally, you should only set one port number here. For most

  deployments a single application server won't be a performance

  bottleneck. However you can provide a comma-separated list of

  port numbers here and splunkd will start a load-balanced

  application server on each one.

* At one time, setting this to zero indicated that the web service

  should be run in a legacy mode as a separate service, but as of

  Splunk 8.0 this is no longer supported.

* Default: 8065

 

I am thinking about:

  • Put the logs in DEBUG
  • Adding other ports to start load-balanced application server

 

Any suggestion is really appreciated.

 

Thanks a lot,

Edoardo

Labels (2)
Tags (2)
0 Karma
1 Solution

edoardo_vicendo
Contributor

For the time being I have solved the issue saving the code one piece at a time.

Saving the 200 lines of code in one shot was generating the problem...

 

Restarting Splunk in DEBUG mode can point in the right direction to understand the root cause, but the amount of messages is really huge.

View solution in original post

0 Karma

edoardo_vicendo
Contributor

For the time being I have solved the issue saving the code one piece at a time.

Saving the 200 lines of code in one shot was generating the problem...

 

Restarting Splunk in DEBUG mode can point in the right direction to understand the root cause, but the amount of messages is really huge.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...