Splunk Enterprise

Why am I getting these socket errors?

tkwaller_2
Communicator

HttpListener - Socket error from while accessing /services/streams/search: Broken pipe?

Here's my ulimit info
ulimit -a
core file size (blocks, -c) 0
data seg size (kbytes, -d) unlimited
scheduling priority (-e) 0
file size (blocks, -f) unlimited
pending signals (-i) 31866
max locked memory (kbytes, -l) 64
max memory size (kbytes, -m) unlimited
open files (-n) 10240
pipe size (512 bytes, -p) 8
POSIX message queues (bytes, -q) 819200
real-time priority (-r) 0
stack size (kbytes, -s) 8192
cpu time (seconds, -t) unlimited
max user processes (-u) 31866
virtual memory (kbytes, -v) unlimited
file locks (-x) unlimited

Please help!

0 Karma

ccl0utier
Splunk Employee
Splunk Employee

I suggest you check the following Splunk answer: https://answers.splunk.com/answers/105292/what-is-the-cause-of-these-socket-errors-reported-in-splun...

I'd then check your splunkd.log logs for anything mentioning a limit being hit or something that might help explain that behaviour (probably for the HTTPListener component).

As a last resort, you might want to do a network trace (Wireshark, NetMon, etc...) with or without the help of your network team. That should help you see what is happening from the network side and might help direct where to look for the issue's root cause next.

0 Karma

hettervik
Builder

Hi! Did you ever find out why you were getting the broken pipe warning? I've seem to have encountered the same problem. One observation from my side is that I'm low on free RAM on the machine, but I don't know if this is related or not.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...