Splunk Search

How to resolve ERROR "Failed processing http input"?

JNgoho
Engager

How can we Stop Docker from sending these logs?
We recently disable the ingestion from Docker to Splunk on the Splunk HEC settings.
But after we disable and delete the HEC settings in Splunk this issue occurs.

01-02-2023 09:33:13.494 -0800 ERROR HttpInputDataHandler [54154 HttpDedicatedIoThread-0] - Failed processing http input, token name=n/a, channel=n/a, source_IP=10.22.100.6, reply=4, events_processed=0, http_input_body_size=291831, parsing_err=""
01-02-2023 09:33:13.379 -0800 ERROR HttpInputDataHandler [54154 HttpDedicatedIoThread-0] - Failed processing http input, token name=n/a, channel=n/a, source_IP=10.22.100.6, reply=4, events_processed=0, http_input_body_size=225158, parsing_err=""

We are getting almost 5,000 ERROR every day. 
We try to delete the daemon.json in the docker https://docs.docker.com/config/containers/logging/splunk/

But the docker is still sending error logs.

Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @JNgoho,

Did you restart the container after deleting the daemon.json file?

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

JNgoho
Engager

We restarted the Docker agent, and still error is sending

0 Karma

Hemant_h
Engager

is your issue resolved? Getting the same error on HF for hec tokens

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...