|
Hey guys, Doesn't seem like many people have had problems with the Splunk Web Service hanging on them, but this is somewhat similar to: Basically, I have been testing my Foundstone Vulnerability Scanner on my splunk indexers and search head and it looks like at least one of servers has its Splunk Web Service die. Port is reachable via telnet, and splunk status states that the service is up, but the site itself is unreachable. I simulated the situation and tailed the logs and see these types of errors: splunkd.log06-22-2010 20:42:42.816 ERROR NetUtils - SSL_ERROR_SSL in SSL_write. nbytes=-1, Error = error:140D00CF:SSL routines:SSL_write:protocol is shutdown 06-22-2010 20:42:43.210 ERROR TcpInputFd - SSL Error = error:1407609C:SSL routines:SSL23_GET_CLIENT_HELLO:http request 06-22-2010 20:45:11.376 INFO TailingProcessor - File descriptor cache is full (64), trimming... web_service.logThis is the error message that appears right before it hangs: 2010-06-18 19:05:05,842 ERROR [4c1798223163010d0] root:120 - ENGINE: Error in HTTP server: shutting down Anyone ever have the same issue? I also ran splunk diag so that I can open support ticket but just wanted to see if anyone else has ever had this problem. Let me know. Thanks Guys! Brian |
|
Can you check 2 things for me: 1) does a ./splunk restart splunkweb fix the hang? (or does it time out) 2) Can you run searches in CLI mode? I have definitely seen this issue come up, but am unsure if it is exactly the same issue or not, however, if the two above happen then we already have a fix for it. Contacting support would probably be the best way for you to get this issue troubleshooted further, and receive the new patch. Let me know on the above two conditions...
Thanks Brian
(23 Jun '10, 01:13)
balbano
1
As a short-term remedy... I set up CRON to restart service once a day...
(23 Jun '10, 01:14)
balbano
|
