Splunk Enterprise

Why am I getting these socket errors?

tkwaller_2
Communicator

HttpListener - Socket error from while accessing /services/streams/search: Broken pipe?

Here's my ulimit info
ulimit -a
core file size (blocks, -c) 0
data seg size (kbytes, -d) unlimited
scheduling priority (-e) 0
file size (blocks, -f) unlimited
pending signals (-i) 31866
max locked memory (kbytes, -l) 64
max memory size (kbytes, -m) unlimited
open files (-n) 10240
pipe size (512 bytes, -p) 8
POSIX message queues (bytes, -q) 819200
real-time priority (-r) 0
stack size (kbytes, -s) 8192
cpu time (seconds, -t) unlimited
max user processes (-u) 31866
virtual memory (kbytes, -v) unlimited
file locks (-x) unlimited

Please help!

0 Karma

ccl0utier
Splunk Employee
Splunk Employee

I suggest you check the following Splunk answer: https://answers.splunk.com/answers/105292/what-is-the-cause-of-these-socket-errors-reported-in-splun...

I'd then check your splunkd.log logs for anything mentioning a limit being hit or something that might help explain that behaviour (probably for the HTTPListener component).

As a last resort, you might want to do a network trace (Wireshark, NetMon, etc...) with or without the help of your network team. That should help you see what is happening from the network side and might help direct where to look for the issue's root cause next.

0 Karma

hettervik
Builder

Hi! Did you ever find out why you were getting the broken pipe warning? I've seem to have encountered the same problem. One observation from my side is that I'm low on free RAM on the machine, but I don't know if this is related or not.

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...