Splunk Search

Problem running "search" example in c# SDK

afd0174
Explorer

Hi,

I have a question about the Splunk C# SDK. I have successfully built the SDK and can use the example submit() program to submit test data to my splunk instance. When I invoke the example search() program to retrieve the same data I submitted, I get some of my results printed to the command window, but then an exception is thrown:

Unhandled Exception: System.Net.WebException: The request was aborted: The connection was closed unexpectedly

I've tried modifying a number of parameter values on the HttpWebRequest object within the Send() method of the HttpService object without success (e.g. KeepAlive = false, large values for all of the timeout parameters). Any ideas on what the problem might be? Thanks.

-Andy

Tags (4)
0 Karma
1 Solution

ywu_splunk
Splunk Employee
Splunk Employee

I'd suggest using fiddler to trace http if you have not done so. Below is how to do so.

You may also experiment with different searches with results of different sizes and speeds.

Install Fiddler
http://fiddler2.com/get-fiddler

Pick version 2 release on the right.

After installation. Go to Tools->Fidder Options->HTTPS tab. Check everything to enable full https decryption.

View solution in original post

araitz
Splunk Employee
Splunk Employee

Did you try https?

0 Karma

ywu_splunk
Splunk Employee
Splunk Employee

I'd suggest using fiddler to trace http if you have not done so. Below is how to do so.

You may also experiment with different searches with results of different sizes and speeds.

Install Fiddler
http://fiddler2.com/get-fiddler

Pick version 2 release on the right.

After installation. Go to Tools->Fidder Options->HTTPS tab. Check everything to enable full https decryption.

afd0174
Explorer

OK, thanks, I'll give it a try.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...