Splunk Search

How to resolve ERROR "Failed processing http input"?

JNgoho
Engager

How can we Stop Docker from sending these logs?
We recently disable the ingestion from Docker to Splunk on the Splunk HEC settings.
But after we disable and delete the HEC settings in Splunk this issue occurs.

01-02-2023 09:33:13.494 -0800 ERROR HttpInputDataHandler [54154 HttpDedicatedIoThread-0] - Failed processing http input, token name=n/a, channel=n/a, source_IP=10.22.100.6, reply=4, events_processed=0, http_input_body_size=291831, parsing_err=""
01-02-2023 09:33:13.379 -0800 ERROR HttpInputDataHandler [54154 HttpDedicatedIoThread-0] - Failed processing http input, token name=n/a, channel=n/a, source_IP=10.22.100.6, reply=4, events_processed=0, http_input_body_size=225158, parsing_err=""

We are getting almost 5,000 ERROR every day. 
We try to delete the daemon.json in the docker https://docs.docker.com/config/containers/logging/splunk/

But the docker is still sending error logs.

Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @JNgoho,

Did you restart the container after deleting the daemon.json file?

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

JNgoho
Engager

We restarted the Docker agent, and still error is sending

0 Karma

Hemant_h
Engager

is your issue resolved? Getting the same error on HF for hec tokens

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...