Splunk Search

Problem running "search" example in c# SDK

afd0174
Explorer

Hi,

I have a question about the Splunk C# SDK. I have successfully built the SDK and can use the example submit() program to submit test data to my splunk instance. When I invoke the example search() program to retrieve the same data I submitted, I get some of my results printed to the command window, but then an exception is thrown:

Unhandled Exception: System.Net.WebException: The request was aborted: The connection was closed unexpectedly

I've tried modifying a number of parameter values on the HttpWebRequest object within the Send() method of the HttpService object without success (e.g. KeepAlive = false, large values for all of the timeout parameters). Any ideas on what the problem might be? Thanks.

-Andy

Tags (4)
0 Karma
1 Solution

ywu_splunk
Splunk Employee
Splunk Employee

I'd suggest using fiddler to trace http if you have not done so. Below is how to do so.

You may also experiment with different searches with results of different sizes and speeds.

Install Fiddler
http://fiddler2.com/get-fiddler

Pick version 2 release on the right.

After installation. Go to Tools->Fidder Options->HTTPS tab. Check everything to enable full https decryption.

View solution in original post

araitz
Splunk Employee
Splunk Employee

Did you try https?

0 Karma

ywu_splunk
Splunk Employee
Splunk Employee

I'd suggest using fiddler to trace http if you have not done so. Below is how to do so.

You may also experiment with different searches with results of different sizes and speeds.

Install Fiddler
http://fiddler2.com/get-fiddler

Pick version 2 release on the right.

After installation. Go to Tools->Fidder Options->HTTPS tab. Check everything to enable full https decryption.

afd0174
Explorer

OK, thanks, I'll give it a try.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...