Splunk Enterprise

Read Time Out Error: Splunk Enterprise 7.1.0

samnathan
Explorer

While inputting a Apache Archive file in ASCII format, 20.7 MB gzip compressed, 205.2 MB uncompressed am getting a "Read Timeout" error. This log/ASCII file has one line per request, with the following columns:
1. host making the request. A hostname when possible, otherwise the Internet address if the name could not be looked up.
2. timestamp in the format "DAY MON DD HH:MM:SS YYYY", where DAY is the day of the week, MON is the name of the month, DD is the day of the month, HH:MM:SS is the time of day using a 24-hour clock, and YYYY is the year. The timezone is -0400.
3. request given in quotes.
4. HTTP reply code.
5. bytes in the reply

Can someone help please?

Tags (1)
0 Karma

samnathan
Explorer

I tried restarting Splunk and attempted "Upload." It gets stuck at "Generating Data Preview" and gets "Read Timeout" throws error. It's a free dataset a trace containing one month's worth of all HTTP requests to the NASA Kennedy Space Center WWW server in Florida. If someone wants to try please let me know. I don't have enough Karma points to share the URL. However you may find it in ita"dot"ee"dot"lbl"dot"gov website.

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...