Splunk Enterprise

Why am I getting these socket errors?


HttpListener - Socket error from while accessing /services/streams/search: Broken pipe?

Here's my ulimit info
ulimit -a
core file size (blocks, -c) 0
data seg size (kbytes, -d) unlimited
scheduling priority (-e) 0
file size (blocks, -f) unlimited
pending signals (-i) 31866
max locked memory (kbytes, -l) 64
max memory size (kbytes, -m) unlimited
open files (-n) 10240
pipe size (512 bytes, -p) 8
POSIX message queues (bytes, -q) 819200
real-time priority (-r) 0
stack size (kbytes, -s) 8192
cpu time (seconds, -t) unlimited
max user processes (-u) 31866
virtual memory (kbytes, -v) unlimited
file locks (-x) unlimited

Please help!

0 Karma

Splunk Employee
Splunk Employee

I suggest you check the following Splunk answer: https://answers.splunk.com/answers/105292/what-is-the-cause-of-these-socket-errors-reported-in-splun...

I'd then check your splunkd.log logs for anything mentioning a limit being hit or something that might help explain that behaviour (probably for the HTTPListener component).

As a last resort, you might want to do a network trace (Wireshark, NetMon, etc...) with or without the help of your network team. That should help you see what is happening from the network side and might help direct where to look for the issue's root cause next.

0 Karma


Hi! Did you ever find out why you were getting the broken pipe warning? I've seem to have encountered the same problem. One observation from my side is that I'm low on free RAM on the machine, but I don't know if this is related or not.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...