Splunk Dev

104, Connection Reset by Peer error

loginsoft
Loves-to-Learn Lots

We created a Splunk Add-on for one of our customers. We are able to call the Rest API and index the data in our environment. But when our client installed the Add-on he gets the below error message. 

Error, connection aborted , 104, Connection Reset by Peer error. Below is the screenshot of the log.

We deployed the same AWS and GCP and it is working fine except in client environment.  

We did a curl to the URL from the client server and it is working fine. Also the same URL is used in Splunk by our client in other Apps.

Can someone kindly help us here. We burned our all our debugging options. 

image001.jpg

 

 

 

 

Labels (4)
0 Karma

livehybrid
Builder

Does the customer have an outbound firewall/security group that could be blocking the connection, or a transparent proxy that is filtering/blocking the traffic?

If you're using SplunkCloud and connecting to a port other than 443 then you might need to request that it be opened up by CloudOps via a support ticket.

 

Tags (1)
0 Karma

loginsoft
Loves-to-Learn Lots

Thanks @livehybrid  for the reply.

Our customer is using on-prem instance. Also we queried the URL using wget command in splunk. It is working with wget. So now, will it be still issue with Firewall/Security Group/Filtering? 

 

0 Karma

livehybrid
Builder

In that case its unlikely to be firewall related!

The other thing I was wondering is could it be connecting on the wrong protocol? e.g. can you confirm that you're connecting with HTTPS if the endpoint is HTTPS? 

The other thing to check for is any proxies in the way that you might not go through when testing in the CLI - its worth checking in server.conf for a [proxyConfig] stanza, and in /opt/splunk/etc/splunk-launch.conf for any environment variable setting of proxies.

 

0 Karma

loginsoft
Loves-to-Learn Lots

@livehybrid  yes it is Https to Https call. Will check the config stanza and get back to you.

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...