-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Akamai-ULS Stops Sending Messages to Splunk Due to HTTP Aggregation Queue Being Full #77
Comments
Hi @sethumadhav07 , Do you have any insight (maybe on the SPLUNK end) why the data could not be delivered? Any Error number or anything you could point us to? I am seeing your point that ULS should be a little be more verbose about whats going on on the HTTP level - I will try to get a grip on the sending function and force it to spit out more logging details |
I have added a more verbose output for HTTP transmission into the "development" branch - the version tag there should be 1.8.4-alpha Feel free to plunge that version into your setup and see if you're able to catch the reason why the transmission fails best |
Thanks Mike. I will incorporate the changes into mine and see. It happens only after a certain period; it can't be easily reproduced. |
I am closing this issue for now. Will reopen it if I determine that the issue on your side. |
I am attaching the logs. You can see that, it gets stuck without any error . All you can see is this pattern: UlsOutput Trying to send data via HTTP Please let me know if you need anything else from me. |
Hi @sethumadhav07 , I'll gonna have a look at this ! |
Hi @sethumadhav07 , sorry for being a little silent the last couple of days - lots of stuff going on ;) So I did now 2 things: please give the latest development version a run and report back to me. Bizarre thing! Even with the test webserver I can produce specific errors and get proper output ... so I am more than keen to understand what is going on here ;) best |
I'll try out the latest development version and let you know what happens. Unfortunately, the problem is difficult to reproduce, and only occurs after the pod has been running for several days. |
Hi @sethumadhav07 , quick ping if you have spotted the behavior again, i am planning to release the "new" version within the next couple of $days/$weeks |
hi mike, This issue is still happening. I have given this less importance because it is not happening in production and only happens in our testing environment. whenever i get time, i will try to investigate further. if you can put your changes in a seperate branch and share here, that is good. if not, i can always look into history. please go ahead and release the new version. Regards, |
Hi Sethu, happy new year. We have just released the latest ULS version. What should we do with this ticket? Best |
Description:
I am encountering an issue with the Akamai-ULS app, where, in some cases, it stops sending eaa access log messages to Splunk because it gets stuck for an unknown reason. This issue seems to be related to the HTTP Aggregation queue getting full and not clearing up. As a result, no messages are being sent to Splunk for extended periods.
Observed Behavior:
Configuration:
Below is the relevant configuration:
Expected Behavior:
Request for Assistance:
Additional Information:
It’s unclear why the HTTP sends fail, as the error message does not indicate the specific reason. It would be beneficial if a more detailed error message could be logged, providing insights into the failure reason.
ULS Version
1.8.3
The text was updated successfully, but these errors were encountered: