Splunk Search

How to resolve ERROR "Failed processing http input"?

JNgoho
Engager

How can we Stop Docker from sending these logs?
We recently disable the ingestion from Docker to Splunk on the Splunk HEC settings.
But after we disable and delete the HEC settings in Splunk this issue occurs.

01-02-2023 09:33:13.494 -0800 ERROR HttpInputDataHandler [54154 HttpDedicatedIoThread-0] - Failed processing http input, token name=n/a, channel=n/a, source_IP=10.22.100.6, reply=4, events_processed=0, http_input_body_size=291831, parsing_err=""
01-02-2023 09:33:13.379 -0800 ERROR HttpInputDataHandler [54154 HttpDedicatedIoThread-0] - Failed processing http input, token name=n/a, channel=n/a, source_IP=10.22.100.6, reply=4, events_processed=0, http_input_body_size=225158, parsing_err=""

We are getting almost 5,000 ERROR every day. 
We try to delete the daemon.json in the docker https://docs.docker.com/config/containers/logging/splunk/

But the docker is still sending error logs.

Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @JNgoho,

Did you restart the container after deleting the daemon.json file?

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

JNgoho
Engager

We restarted the Docker agent, and still error is sending

0 Karma

Hemant_h
Engager

is your issue resolved? Getting the same error on HF for hec tokens

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...