Splunk Search

Read error when exporting to CSV file

deca2499
Engager

Hey all,

I hope this is the correct board for this question, but I am having an issue when I try to export a search to CSV from a search. I keep getting the following error when trying to run the export. Has anyone seen this and how to resolve it? I am using version 8.1.2 FWIW.

Unrecoverable error in the server.
Traceback (most recent call last):
  File "C:\Program Files\Splunk\Python-3.7\lib\site-packages\cherrypy\_cpwsgi.py", line 184, in trap
    return func(*args, **kwargs)
  File "C:\Program Files\Splunk\Python-3.7\lib\site-packages\cherrypy\_cpwsgi.py", line 277, in __next__
    return next(self.iter_response)
  File "C:\Program Files\Splunk\Python-3.7\lib\site-packages\cherrypy\lib\encoding.py", line 99, in encoder
    for chunk in body:
  File "C:\Program Files\Splunk\Python-3.7\lib\site-packages\splunk\rest\__init__.py", line 698, in readall
    data = response.read(blocksize)
  File "C:\Program Files\Splunk\Python-3.7\lib\http\client.py", line 457, in read
    n = self.readinto(b)
  File "C:\Program Files\Splunk\Python-3.7\lib\http\client.py", line 501, in readinto
    n = self.fp.readinto(b)
  File "C:\Program Files\Splunk\Python-3.7\lib\socket.py", line 589, in readinto
    return self._sock.recv_into(b)
  File "C:\Program Files\Splunk\Python-3.7\lib\ssl.py", line 1071, in recv_into
    return self.read(nbytes, buffer)
  File "C:\Program Files\Splunk\Python-3.7\lib\ssl.py", line 929, in read
    return self._sslobj.read(len, buffer)
socket.timeout: The read operation timed out

THanks!

 

Labels (1)
Tags (2)
0 Karma

scelikok
Champion

Hi @deca2499,

How big is your result? Do you get the same error even the result is a few small events? 

If this reply helps you an upvote is appreciated.
0 Karma

deca2499
Engager

Hi @scelikok ,

I was just able to get the export done with 14k results, but when I bumped it up to 24 hours with 330k results, it failed and gave me that error.

0 Karma

deca2499
Engager

Has anyone seen this in any way? We are running the free version of Splunk and it seems like whatever time range I choose, I get the same error.

Tags (1)
0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!