Splunk Search

I am getting search error "HttpListener...sent a 0 byte response after earlier claiming a Content-Length of 641!"?

mikehsieh
Engager

I am getting ERROR HttpListener when I search and do not get any data - this error is in splunk server 6.2.3

06-19-2015 13:54:00.722 -0400 ERROR HttpListener - Exception while processing request from 11.48.178.51 for /en-US/api/shelper?snippet=true&snippetEmbedJS=false&namespace=search&search=search+host%3D%2211.48.222.101%22&useTypeahead=true&useAssistant=true&showCommandHelp=true&showCommandHistory=true&showFieldInfo=false&_=1434736433926: Connection closed by peer
06-19-2015 13:54:00.722 -0400 ERROR HttpListener - Handler for /en-US/api/shelper?snippet=true&snippetEmbedJS=false&namespace=search&search=search+host%3D%2211.48.222.101%22&useTypeahead=true&useAssistant=true&showCommandHelp=true&showCommandHistory=true&showFieldInfo=false&_=1434736433926 sent a 0 byte response after earlier claiming a Content-Length of 641!
Tags (1)

despachoSTD
Explorer

Chech if you have disabled (or even deleted) the default data input pointing at:

$SPLUNK_HOME$/var/spool/dbmon/*.dbmonevt"

or have any problem in creating files in that location.

It turns out that the dbx app writes the results in that kind of files in that dir, and later Splunk indexes (and deletes) that files to read the results.

0 Karma

despachoSTD
Explorer

Beware that if you simply start the data input with all the files in the dir, the system will perform all the pending indexings, potentially causing licensing issues and/or repetitions.

If you want to start clean, stop splunk, delete all the files in the dir, start splunk and enable the data input again.

0 Karma

klsio
Explorer

I have same error..

0 Karma

gsawyer1
Engager

I had a similar error and was unable to login to my Splunk instance via web. I cleared the cache and all history etc from the browser, restarted the computer, and lo and behold, problem disappeared. But, my errors were related to the display of webfonts when I tried to view an XML dashboard's source in plaintext, and resulted in Winsock error 10045 (connection reset). They ended with:
sent a 0 byte response after earlier claiming a Content-Length of xxxx!

So maybe that will help you or someone else....

0 Karma

thashmi
Splunk Employee
Splunk Employee

If you could brief about your webui not loading issue and how did you resolve it.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Look at the dates 🙂

You're responding to an almost 8-years old thread regarding a 6.x Splunk version.

I wouldn't expect a reasonable response here.

0 Karma

mekamundia
Explorer

I am receiving this error every day too

0 Karma

karthikannan
New Member

Does anybody know the solution for this issue. I'm facing the same....

0 Karma

l-mss-n3
New Member

I have been working with the same problem, Did you found any solution?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...