Splunk Enterprise

Recommendations for Splunkd daemon error?

JohnHC
New Member

All,

I am having an issue with splunk and uploading Pcap files to the server we are running on prem. When I attempt to upload a Pcap file via the data inputs option I receive the following error. 

Encountered the following error while trying to save: Splunkd daemon is not responding: ('Error connecting to /servicesNS/admin/launcher/data/inputs/upload_pcap: The read operation timed out',)

My thinking is it could be too big and is timing out the daemon. If that is the case can this timeout be edited? 

Pcap files are in the 139MB size range. 

Thank you for any recommendations or insight. 

Labels (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @JohnHC,

That cli command is the same function as uploading using GUI. You can set index and sourcetype if you will.

As a sample;

[root@myserver bin] ./streamfwd -r my.pcap --index pcap_index
If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @JohnHC,

If you have access to command line you can try cli commands;

[root@myserver bin] ./streamfwd -r my.pcap

https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/streamfwdcommandlineoptions#Re...

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

JohnHC
New Member

That command is not an issue. We are attempting to input the pcap file into the input data field so other users can perform searches from the Splunk search GUI.  We are attempting to upload the files here and are getting the error. SplunkInput.PNG

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...