Splunk Search

"[Errno 111] Connection refused" when I restart Splunk on my HF

GaetanVP
Contributor

Hello Splunkers,

I am facing some errors every time I relaunch my Splunk service on my HF.
Inside splunkd.log I have this :

 

error=Splunkd daemon is not responding: ('Error connecting to https://127.0.0.1:8089//services/server/roles: [Errno 111] Connection refused',)

 

I am sure that spunkd is running on port 8089 and I also checked that my instance's firewall is not blocking this port.

Maybe it's just normal to see those errors at Splunk startup ?
Thanks for your help,

GaetanVP


0 Karma
1 Solution

schose
Builder

Hi GaetanVP,

I see the same errormessages in _internal. They are coming from modular input assist::supervisor_modular_input.py and assist::uiassets_modular_input.py .. nothing to worry about.. only seems like a timing issue when stop splunkd the modular inputs are not able to connect at this point in time.

loglevel is shown as INFO. logfiles are  splunk_assist_*.log

best regards,

Andreas

View solution in original post

GaetanVP
Contributor

Ok, thanks for the info!

Regards,
GaetanVP

0 Karma

schose
Builder

Hi GaetanVP,

I see the same errormessages in _internal. They are coming from modular input assist::supervisor_modular_input.py and assist::uiassets_modular_input.py .. nothing to worry about.. only seems like a timing issue when stop splunkd the modular inputs are not able to connect at this point in time.

loglevel is shown as INFO. logfiles are  splunk_assist_*.log

best regards,

Andreas

Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...