Splunk Enterprise

Read Time Out Error: Splunk Enterprise 7.1.0

samnathan
Explorer

While inputting a Apache Archive file in ASCII format, 20.7 MB gzip compressed, 205.2 MB uncompressed am getting a "Read Timeout" error. This log/ASCII file has one line per request, with the following columns:
1. host making the request. A hostname when possible, otherwise the Internet address if the name could not be looked up.
2. timestamp in the format "DAY MON DD HH:MM:SS YYYY", where DAY is the day of the week, MON is the name of the month, DD is the day of the month, HH:MM:SS is the time of day using a 24-hour clock, and YYYY is the year. The timezone is -0400.
3. request given in quotes.
4. HTTP reply code.
5. bytes in the reply

Can someone help please?

Tags (1)
0 Karma

samnathan
Explorer

I tried restarting Splunk and attempted "Upload." It gets stuck at "Generating Data Preview" and gets "Read Timeout" throws error. It's a free dataset a trace containing one month's worth of all HTTP requests to the NASA Kennedy Space Center WWW server in Florida. If someone wants to try please let me know. I don't have enough Karma points to share the URL. However you may find it in ita"dot"ee"dot"lbl"dot"gov website.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...