Splunk Search

How to resolve ERROR "Failed processing http input"?

JNgoho
Engager

How can we Stop Docker from sending these logs?
We recently disable the ingestion from Docker to Splunk on the Splunk HEC settings.
But after we disable and delete the HEC settings in Splunk this issue occurs.

01-02-2023 09:33:13.494 -0800 ERROR HttpInputDataHandler [54154 HttpDedicatedIoThread-0] - Failed processing http input, token name=n/a, channel=n/a, source_IP=10.22.100.6, reply=4, events_processed=0, http_input_body_size=291831, parsing_err=""
01-02-2023 09:33:13.379 -0800 ERROR HttpInputDataHandler [54154 HttpDedicatedIoThread-0] - Failed processing http input, token name=n/a, channel=n/a, source_IP=10.22.100.6, reply=4, events_processed=0, http_input_body_size=225158, parsing_err=""

We are getting almost 5,000 ERROR every day. 
We try to delete the daemon.json in the docker https://docs.docker.com/config/containers/logging/splunk/

But the docker is still sending error logs.

Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @JNgoho,

Did you restart the container after deleting the daemon.json file?

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

JNgoho
Engager

We restarted the Docker agent, and still error is sending

0 Karma

Hemant_h
Engager

is your issue resolved? Getting the same error on HF for hec tokens

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...