<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Noob - Can't add TCP Port 9997 - Error in handler 'raw' in Security</title>
    <link>https://community.splunk.com/t5/Security/Noob-Can-t-add-TCP-Port-9997-Error-in-handler-raw/m-p/84309#M2791</link>
    <description>&lt;P&gt;On forwarder:&lt;BR /&gt;
ttcp       0      0 0.0.0.0:9997            0.0.0.0:*               LISTEN      14095/splunkd&lt;BR /&gt;&lt;BR /&gt;
tcp        0      0 FORWARDERIP:33750    SERVERIP:9997     TIME_WAIT   -&lt;BR /&gt;&lt;BR /&gt;
tcp        0      0 FORWARDERIP:32878    SERVERIP:9997     ESTABLISHED 14095/splunkd&lt;BR /&gt;&lt;BR /&gt;
tcp        0      0 FORWARDERIP:33749    SERVERIP:9997     TIME_WAIT   -&lt;BR /&gt;&lt;BR /&gt;
tcp        0      0 FORWARDERIP:33751    SERVERIP:9997     ESTABLISHED 14095/splunkd&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 09:28:23 GMT</pubDate>
    <dc:creator>franklovecchio</dc:creator>
    <dc:date>2020-09-28T09:28:23Z</dc:date>
    <item>
      <title>Noob - Can't add TCP Port 9997 - Error in handler 'raw'</title>
      <link>https://community.splunk.com/t5/Security/Noob-Can-t-add-TCP-Port-9997-Error-in-handler-raw/m-p/84306#M2788</link>
      <description>&lt;P&gt;So, I'm new, and having a bit of trouble &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I have a Splunk instance running, we'll call it my server (can access GUI), that I'm trying to configure to listen on port 9997.  I have another box which is setup as a "forwarder", and to configure it, I ran "splunk add forward-server serverIP:9997" and "splunk set splunkd-port 9997" (I changed the mgmt port because not changing it didn't work either).&lt;/P&gt;

&lt;P&gt;So, from the GUI on the server, I click "Manage", "Data Inputs", "TCP", and I try to add a new port to receive data on (9997).  When I say add syslog from all incoming hosts on this port, I get the error "Encountered the following error while trying to save: In handler 'raw': Parameter name: TCP port 9997 is not available".  Why would this be?  I'm on amazon ec2, and definitely have the ports 9997, 8000, and 8089 opened.  Please help!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2011 17:13:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Noob-Can-t-add-TCP-Port-9997-Error-in-handler-raw/m-p/84306#M2788</guid>
      <dc:creator>franklovecchio</dc:creator>
      <dc:date>2011-04-19T17:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Noob - Can't add TCP Port 9997 - Error in handler 'raw'</title>
      <link>https://community.splunk.com/t5/Security/Noob-Can-t-add-TCP-Port-9997-Error-in-handler-raw/m-p/84307#M2789</link>
      <description>&lt;P&gt;netstat -tnap | grep 9997&lt;/P&gt;

&lt;P&gt;anything else currently bound to that port?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2011 17:14:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Noob-Can-t-add-TCP-Port-9997-Error-in-handler-raw/m-p/84307#M2789</guid>
      <dc:creator>netwrkr</dc:creator>
      <dc:date>2011-04-19T17:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Noob - Can't add TCP Port 9997 - Error in handler 'raw'</title>
      <link>https://community.splunk.com/t5/Security/Noob-Can-t-add-TCP-Port-9997-Error-in-handler-raw/m-p/84308#M2790</link>
      <description>&lt;P&gt;I don't think so - looks about right to me!&lt;/P&gt;

&lt;P&gt;On server:&lt;BR /&gt;
tcp        0      0 SERVERIP:9997         FORWARDERIP:33749        ESTABLISHED 10923/splunkd&lt;BR /&gt;&lt;BR /&gt;
tcp        0      0 SERVERIP:9997         FORWARDERIP:32878        ESTABLISHED 10923/splunkd&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2011 17:22:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Noob-Can-t-add-TCP-Port-9997-Error-in-handler-raw/m-p/84308#M2790</guid>
      <dc:creator>franklovecchio</dc:creator>
      <dc:date>2011-04-19T17:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Noob - Can't add TCP Port 9997 - Error in handler 'raw'</title>
      <link>https://community.splunk.com/t5/Security/Noob-Can-t-add-TCP-Port-9997-Error-in-handler-raw/m-p/84309#M2791</link>
      <description>&lt;P&gt;On forwarder:&lt;BR /&gt;
ttcp       0      0 0.0.0.0:9997            0.0.0.0:*               LISTEN      14095/splunkd&lt;BR /&gt;&lt;BR /&gt;
tcp        0      0 FORWARDERIP:33750    SERVERIP:9997     TIME_WAIT   -&lt;BR /&gt;&lt;BR /&gt;
tcp        0      0 FORWARDERIP:32878    SERVERIP:9997     ESTABLISHED 14095/splunkd&lt;BR /&gt;&lt;BR /&gt;
tcp        0      0 FORWARDERIP:33749    SERVERIP:9997     TIME_WAIT   -&lt;BR /&gt;&lt;BR /&gt;
tcp        0      0 FORWARDERIP:33751    SERVERIP:9997     ESTABLISHED 14095/splunkd&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:28:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Noob-Can-t-add-TCP-Port-9997-Error-in-handler-raw/m-p/84309#M2791</guid>
      <dc:creator>franklovecchio</dc:creator>
      <dc:date>2020-09-28T09:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: Noob - Can't add TCP Port 9997 - Error in handler 'raw'</title>
      <link>https://community.splunk.com/t5/Security/Noob-Can-t-add-TCP-Port-9997-Error-in-handler-raw/m-p/84310#M2792</link>
      <description>&lt;P&gt;You're mixing different types of inputs here. I'm unsure as to whether that in itself would cause the problems you describe, but when receiving forwarded data from another Splunk instance, you should configure a corresponding receiver rather than a 'raw' data input. Go to Manager -&amp;gt; Forwarding and receiving -&amp;gt; Configure receiving -&amp;gt; Add new. Since you have established connections on port 9997 on the server it seems someone might already have done this!&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2011 11:31:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Noob-Can-t-add-TCP-Port-9997-Error-in-handler-raw/m-p/84310#M2792</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-04-20T11:31:03Z</dc:date>
    </item>
  </channel>
</rss>

