Splunk Search

How to resolve ERROR "Failed processing http input"?

JNgoho
Engager

How can we Stop Docker from sending these logs?
We recently disable the ingestion from Docker to Splunk on the Splunk HEC settings.
But after we disable and delete the HEC settings in Splunk this issue occurs.

01-02-2023 09:33:13.494 -0800 ERROR HttpInputDataHandler [54154 HttpDedicatedIoThread-0] - Failed processing http input, token name=n/a, channel=n/a, source_IP=10.22.100.6, reply=4, events_processed=0, http_input_body_size=291831, parsing_err=""
01-02-2023 09:33:13.379 -0800 ERROR HttpInputDataHandler [54154 HttpDedicatedIoThread-0] - Failed processing http input, token name=n/a, channel=n/a, source_IP=10.22.100.6, reply=4, events_processed=0, http_input_body_size=225158, parsing_err=""

We are getting almost 5,000 ERROR every day. 
We try to delete the daemon.json in the docker https://docs.docker.com/config/containers/logging/splunk/

But the docker is still sending error logs.

Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @JNgoho,

Did you restart the container after deleting the daemon.json file?

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

JNgoho
Engager

We restarted the Docker agent, and still error is sending

0 Karma

Hemant_h
Engager

is your issue resolved? Getting the same error on HF for hec tokens

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...