Splunk Enterprise

Read Time Out Error: Splunk Enterprise 7.1.0

samnathan
Explorer

While inputting a Apache Archive file in ASCII format, 20.7 MB gzip compressed, 205.2 MB uncompressed am getting a "Read Timeout" error. This log/ASCII file has one line per request, with the following columns:
1. host making the request. A hostname when possible, otherwise the Internet address if the name could not be looked up.
2. timestamp in the format "DAY MON DD HH:MM:SS YYYY", where DAY is the day of the week, MON is the name of the month, DD is the day of the month, HH:MM:SS is the time of day using a 24-hour clock, and YYYY is the year. The timezone is -0400.
3. request given in quotes.
4. HTTP reply code.
5. bytes in the reply

Can someone help please?

Tags (1)
0 Karma

samnathan
Explorer

I tried restarting Splunk and attempted "Upload." It gets stuck at "Generating Data Preview" and gets "Read Timeout" throws error. It's a free dataset a trace containing one month's worth of all HTTP requests to the NASA Kennedy Space Center WWW server in Florida. If someone wants to try please let me know. I don't have enough Karma points to share the URL. However you may find it in ita"dot"ee"dot"lbl"dot"gov website.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...