Splunk Enterprise

Read Time Out Error: Splunk Enterprise 7.1.0

samnathan
Explorer

While inputting a Apache Archive file in ASCII format, 20.7 MB gzip compressed, 205.2 MB uncompressed am getting a "Read Timeout" error. This log/ASCII file has one line per request, with the following columns:
1. host making the request. A hostname when possible, otherwise the Internet address if the name could not be looked up.
2. timestamp in the format "DAY MON DD HH:MM:SS YYYY", where DAY is the day of the week, MON is the name of the month, DD is the day of the month, HH:MM:SS is the time of day using a 24-hour clock, and YYYY is the year. The timezone is -0400.
3. request given in quotes.
4. HTTP reply code.
5. bytes in the reply

Can someone help please?

Tags (1)
0 Karma

samnathan
Explorer

I tried restarting Splunk and attempted "Upload." It gets stuck at "Generating Data Preview" and gets "Read Timeout" throws error. It's a free dataset a trace containing one month's worth of all HTTP requests to the NASA Kennedy Space Center WWW server in Florida. If someone wants to try please let me know. I don't have enough Karma points to share the URL. However you may find it in ita"dot"ee"dot"lbl"dot"gov website.

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...