Security

SplunkWeb - Your network connection may have been lost or Splunk web may be down?

Michael_Wilde
Splunk Employee
Splunk Employee

Whats the deal with that error? What is splunk doing when that happens? Assuming its making some sort of connection to "splunkd", can i control the timeout?

Tags (1)
1 Solution

sideview
SplunkTrust
SplunkTrust

It means the browser lost the ability to talk to SplunkWeb for more than some number of seconds.

More literally it means an HTTP request reported http status code 0, which is the browsers way of telling us that it never heard back. Im not sure how many seconds it takes of total silence before the browser gives up but I'm pretty sure it's not configurable.

Assuming someone didnt actually restart SplunkWeb out from under you, it sounds like your server or maybe just SplunkWeb, is extremely busy. I get this once in a while too.

View solution in original post

ii_splunk
Path Finder

I have just recently started getting this message and it seems to be correlated to these messages in the splunkd.log:

08-02-2012 13:47:07.449 WARN metadata - Could not retrieve totalCount value for a row of type 'sourcetype'. Skipping.
08-02-2012 13:47:09.847 WARN metadata - Could not retrieve totalCount value for a row of type 'sourcetype'. Skipping.
08-02-2012 13:47:13.756 WARN metadata - Could not retrieve totalCount value for a row of type 'source'. Skipping.
08-02-2012 13:47:16.086 WARN metadata - Could not retrieve totalCount value for a row of type 'source'. Skipping.

I only get this on the Summary page. Could my metadata be corrupt? If so how can I fix this?

0 Karma

sideview
SplunkTrust
SplunkTrust

It means the browser lost the ability to talk to SplunkWeb for more than some number of seconds.

More literally it means an HTTP request reported http status code 0, which is the browsers way of telling us that it never heard back. Im not sure how many seconds it takes of total silence before the browser gives up but I'm pretty sure it's not configurable.

Assuming someone didnt actually restart SplunkWeb out from under you, it sounds like your server or maybe just SplunkWeb, is extremely busy. I get this once in a while too.

sideview
SplunkTrust
SplunkTrust

hahaha... nice. Yea its a pretty useful hack. Shame there's not a better way. (Nag somebody!)

0 Karma

Michael_Wilde
Splunk Employee
Splunk Employee

i see an argh filter coming my way!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...