<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SC4S to Splunk Cloud forwarding receiving errors? in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/710841#M3543</link>
    <description>&lt;P&gt;Here is the full env_file&lt;/P&gt;&lt;P&gt;SC4S_SOURCE_SYSLOG_PORTS=514,32514,32601,41514,41601,42514,42601&lt;/P&gt;&lt;P&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_URL=https://&amp;lt;&amp;gt;:3001/services/collector/event&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_TOKEN=&amp;lt;&amp;gt;&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_INDEX=&amp;lt;&amp;gt;&lt;BR /&gt;# SC4S_DEST_SPLUNK_HEC_DEFAULT_MODE=GLOBAL&lt;BR /&gt;# SC4S_DEST_SPLUNK_HEC_DEFAULT_FORMAT=json&lt;BR /&gt;# SC4S_DEST_SPLUNK_HEC_DEFAULT_TLS_VERIFY=no&lt;/P&gt;&lt;P&gt;SC4S_DEST_SPLUNK_HEC_TLS_CA_FILE=/etc/ssl/certs/ca-certificates.crt&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_TLS_CLIENT_CERT=/etc/syslog-ng/tls/splunk.crt&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_TLS_CLIENT_KEY=/etc/syslog-ng/tls/splunk.key&lt;/P&gt;&lt;P&gt;SC4S_SOURCE_TLS_ENABLE=yes&lt;BR /&gt;SC4S_SOURCE_TLS_KEY=/etc/syslog-ng/tls/server.key&lt;BR /&gt;SC4S_SOURCE_TLS_CERT=/etc/syslog-ng/tls/server.pem&lt;/P&gt;&lt;P&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_DISKBUFF_ENABLE=yes&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_DISKBUFF_DIR=/var/lib/sc4s/disk-buffer&lt;/P&gt;&lt;P&gt;SC4S_HEALTH_CHECK_ENABLE=true&lt;BR /&gt;SC4S_LISTEN_INTERNAL_HEALTH_PORT=9129&lt;/P&gt;&lt;P&gt;SC4S_ETC=/etc/syslog-ng&lt;/P&gt;&lt;P&gt;SC4S_LISTEN_CHECKPOINT_SPLUNK_NOISE_CONTROL_SECONDS=30&lt;/P&gt;&lt;P&gt;SC4S_LISTEN_STATUS_PORT=9129&lt;BR /&gt;SC4S_LISTEN_DEFAULT_TCP_PORT=41514&lt;BR /&gt;SC4S_LISTEN_DEFAULT_UDP_PORT=42514&lt;BR /&gt;SC4S_LISTEN_DEFAULT_TLS_PORT=7514&lt;BR /&gt;SC4S_LISTEN_DEFAULT_RFC5426_PORT=41601&lt;BR /&gt;SC4S_LISTEN_DEFAULT_RFC6587_PORT=42601&lt;BR /&gt;SC4S_LISTEN_DEFAULT_RFC5425_PORT=7425&lt;/P&gt;&lt;P&gt;SC4S_HEALTH_CHECK_ENABLE=true&lt;/P&gt;&lt;P&gt;SC4S_DEST_SPLUNK_HEC_BATCH_SIZE=1&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_RETRY_LIMIT=1&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_RETRY_INTERVAL=5&lt;/P&gt;&lt;P&gt;SOURCE_ALL_SET=DEFAULT_TCP,DEFAULT_UDP&lt;/P&gt;&lt;P&gt;# SC4S_SEND_METRICS_TERMINAL=no&lt;/P&gt;&lt;P&gt;SC4S_DEBUG=false&lt;BR /&gt;SC4S_LOG_LEVEL=false&lt;BR /&gt;SC4S_DEFAULT_TIMEZONE=Europe/Berlin&lt;BR /&gt;PYTHONPATH=/var/lib/python-venv/lib/python3.12/site-packages:/etc/syslog-ng/python:/etc/syslog-ng/pylib&lt;BR /&gt;# Tunning settings&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_TIME_REOPEN=30&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_BATCH_LINES=100&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_BATCH_TIMEOUT=5000&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_KEEPALIVE=yes&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_WORKERS=8&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DISKBUFF_ENABLE=yes&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DISKBUFF_RELIABLE=yes&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DISKBUFF_MEMBUFLENGTH=10000&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DISKBUFF_DISKBUFSIZE=200000000&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2025 13:57:58 GMT</pubDate>
    <dc:creator>tigerdice</dc:creator>
    <dc:date>2025-02-06T13:57:58Z</dc:date>
    <item>
      <title>SC4S to Splunk Cloud forwarding receiving errors?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/620383#M1879</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a network background and know a little bit syslog and using the Splunk interface. This is however the first time I'm installing a new Splunk instance.&lt;/P&gt;
&lt;P&gt;I've started up my Splunk cloud trial and spun up SC4S via podman (version 2.39.0) on RHEL 8.2.&lt;/P&gt;
&lt;P&gt;It seems to be running fine, SC4S messages arriving in Splunk Cloud&lt;/P&gt;
&lt;PRE&gt;- - syslog-ng 149 - [meta sequenceId="1"]syslog-ng starting up; version='3.36.1'&lt;BR /&gt;host = splunk-sc4ssource = sc4ssourcetype = sc4s:events&lt;/PRE&gt;
&lt;P&gt;I'm sending syslog from my test ASA to SC4S and with a tcpdump I can see it coming in:&lt;/P&gt;
&lt;PRE&gt;07:46:13.658608 IP xxx.45.78.xxx.syslog &amp;gt; splunk-sc4s.internal.cloudapp.net.syslog: SYSLOG local7.debug, length: 101&lt;BR /&gt;07:46:13.735897 IP xxx.45.78.xxx.syslog &amp;gt; splunk-sc4s.internal.cloudapp.net.syslog: SYSLOG local7.info, length: 183&lt;BR /&gt;07:46:13.962147 IP xxx.45.78.xxx.syslog &amp;gt; splunk-sc4s.internal.cloudapp.net.syslog: SYSLOG local7.info, length: 155&lt;BR /&gt;07:46:16.550565 IP xxx.45.78.xxx.syslog &amp;gt; splunk-sc4s.internal.cloudapp.net.syslog: SYSLOG local7.info, length: 166&lt;/PRE&gt;
&lt;P&gt;Problem is, in Splunk I'm only getting http errors which seems to come from the above syslog messages forwarded by SC4S:&lt;/P&gt;
&lt;PRE&gt;- syslog-ng 149 - [meta sequenceId="18"]curl: error sending HTTP request; url='https://prd-p-xxxxxx.splunkcloud.com:8088/services/collector/event', error='Timeout was reached', worker_index='2', driver='d_hec_fmt#0', location='root generator dest_hec:5:5'&lt;BR /&gt;host = splunk-sc4ssource = sc4ssourcetype = sc4s:events&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;Things I've configured on SC4S, only the basics:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;/etc/sysctl.conf&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE&gt;net.core.rmem_default = 17039360&lt;BR /&gt;net.core.rmem_max = 17039360&lt;BR /&gt;net.ipv4.ip_forward = 1&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;/opt/sc4s/env_file&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_URL=https://prd-p-xxxxx.splunkcloud.com:8088&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_TOKEN=xxxxxxxx-9c3c-4918-8eb3-xxxxxxxxxxxxx&lt;BR /&gt;#Uncomment the following line if using untrusted SSL certificates &lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_TLS_VERIFY=no&lt;/PRE&gt;
&lt;P&gt;In splunk I've created the HEC token:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jell0r_0-1668069246221.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22409iCBBB2CC045ADD49B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jell0r_0-1668069246221.png" alt="jell0r_0-1668069246221.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I've created the Indexes like this, looking at this everything seems to fall in the "main" index instead of "lastchangeindex", looks like that's not right, is it?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jell0r_1-1668069472976.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22410i2720385713B2DB39/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jell0r_1-1668069472976.png" alt="jell0r_1-1668069472976.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I must be missing something obvious here because this should be straightforward right?&lt;/P&gt;
&lt;P&gt;Appreciate any input on this, thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 15:40:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/620383#M1879</guid>
      <dc:creator>jell0r</dc:creator>
      <dc:date>2022-11-10T15:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: SC4S to Splunk Cloud forwarding receiving errors?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/668086#M2621</link>
      <description>&lt;P&gt;No replies, having same issue here.&amp;nbsp; It's something we messed up or isn't documented, just trying to figure out what.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 14:40:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/668086#M2621</guid>
      <dc:creator>RicoViq</dc:creator>
      <dc:date>2023-11-09T14:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: SC4S to Splunk Cloud forwarding receiving errors?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/675413#M2768</link>
      <description>&lt;P&gt;So the issue you are having is the index it lands in correct?&lt;BR /&gt;&lt;BR /&gt;It is likely that SC4S hec client is sending a default index.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Hec clients settings in the payload override the settings you put on the token. Think of those as "if not set by the hec client".&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/FormateventsforHTTPEventCollector#Event_metadata" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/FormateventsforHTTPEventCollector#Event_metadata&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Would check sc4s docs on setting indexes:&amp;nbsp;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/main/configuration/#log-path-overrides-of-index-or-metadata" target="_blank" rel="noopener"&gt;https://splunk.github.io/splunk-connect-for-syslog/main/configuration/#log-path-overrides-of-index-or-metadata&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 16:43:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/675413#M2768</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2024-01-25T16:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: SC4S to Splunk Cloud forwarding receiving errors?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/709318#M3500</link>
      <description>&lt;P&gt;same problem.&amp;nbsp; The index is correct&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;# docker logs -f sc4s&lt;BR /&gt;SC4S_ENV_CHECK_HEC: Splunk HEC connection test successful to index=sddc_internal for sourcetype=sc4s:fallback...&lt;BR /&gt;SC4S_ENV_CHECK_HEC: Splunk HEC connection test successful to index=sddc_internal for sourcetype=sc4s:events...&lt;BR /&gt;syslog-ng checking config&lt;BR /&gt;sc4s version=3.34.1&lt;BR /&gt;Configuring the health check port to: 8080&lt;BR /&gt;[2025-01-21 13:54:30 +0000] [129] [INFO] Starting gunicorn 23.0.0&lt;BR /&gt;[2025-01-21 13:54:30 +0000] [129] [INFO] Listening at: &lt;A href="http://0.0.0.0:8080" target="_blank" rel="noopener"&gt;http://0.0.0.0:8080&lt;/A&gt; (129)&lt;BR /&gt;[2025-01-21 13:54:30 +0000] [129] [INFO] Using worker: sync&lt;BR /&gt;[2025-01-21 13:54:30 +0000] [138] [INFO] Booting worker with pid: 138&lt;BR /&gt;starting syslog-ng&amp;nbsp; no errors on startup but still these sc4s:events keep coming no idea what they are and the are annoying.&amp;nbsp; The index is correct.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 14:24:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/709318#M3500</guid>
      <dc:creator>tigerdice</dc:creator>
      <dc:date>2025-01-21T14:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: SC4S to Splunk Cloud forwarding receiving errors?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/709320#M3501</link>
      <description>&lt;P&gt;Are you also on a cloud trial?&lt;/P&gt;&lt;P&gt;These could just be momentary server busy etc, be sure to check splunk internal logs&amp;nbsp; index=_internal source=*splunkd.log httpinputdatahandler)&amp;nbsp; to see if the payload hit a 503 or something then retried. It is "expected" that hec clients have to handle backpressure&amp;nbsp; or timeouts, so from time to time you may see a failed send, but as long as retry is successful, its "normal" unless you up your indexing layer to handle more traffic uninterrupted.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The error says "timeout reached" so it could be that Splunk was to busy to answer (especially in standalone trail or small test boxes).&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Also please confirm the HEC full URL you are using. I believe you need to put the full URL&lt;BR /&gt;&lt;BR /&gt;https://http-inputs.foo.splunkcloud.com/services/collector/event (or trial equivalient)&lt;BR /&gt;&lt;BR /&gt;OP looks like they configured to just the cloud url on 8088, which is not a correct url for HEC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 14:50:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/709320#M3501</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2025-01-21T14:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: SC4S to Splunk Cloud forwarding receiving errors?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/709447#M3504</link>
      <description>&lt;P&gt;no it is not busy - it is getting basically a 400 error which means format if i take and only have the default destionation be d_hec_default or d_hec_other basically if i go only 2 one of the splunk HEC site it is fine.&amp;nbsp; It only gets the busy or format error on the second site if only the second site is configured so if i switch it whatever is the first site works and whatever is the second site doesnt work.&amp;nbsp; So no it is not busy or that it can not injest the logs it is sc4s doesnt seem to work well with multi destinations.&amp;nbsp; I am looking for help with someone that has done that.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 11:49:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/709447#M3504</guid>
      <dc:creator>tigerdice</dc:creator>
      <dc:date>2025-01-22T11:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: SC4S to Splunk Cloud forwarding receiving errors?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/709448#M3505</link>
      <description>&lt;P&gt;Where are you seeing the 400 error? The Hec client said timeout in this post, didnt seem to mention 400 bad request?&lt;BR /&gt;&lt;BR /&gt;if its format then something is fundamentally wrong with the payload or you sending to the wrong url, etc.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Anyways suggest you post your own post with any info and config, especially the hec url config and any splunk internal logs that align.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Otherwise would try support or the github issues.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;found this issue that sounded kinda similar, but hard to tell without you providing config details or logs.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://github.com/splunk/splunk-connect-for-syslog/issues/1329" target="_blank"&gt;https://github.com/splunk/splunk-connect-for-syslog/issues/1329&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 12:39:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/709448#M3505</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2025-01-22T12:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: SC4S to Splunk Cloud forwarding receiving errors?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/710841#M3543</link>
      <description>&lt;P&gt;Here is the full env_file&lt;/P&gt;&lt;P&gt;SC4S_SOURCE_SYSLOG_PORTS=514,32514,32601,41514,41601,42514,42601&lt;/P&gt;&lt;P&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_URL=https://&amp;lt;&amp;gt;:3001/services/collector/event&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_TOKEN=&amp;lt;&amp;gt;&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_INDEX=&amp;lt;&amp;gt;&lt;BR /&gt;# SC4S_DEST_SPLUNK_HEC_DEFAULT_MODE=GLOBAL&lt;BR /&gt;# SC4S_DEST_SPLUNK_HEC_DEFAULT_FORMAT=json&lt;BR /&gt;# SC4S_DEST_SPLUNK_HEC_DEFAULT_TLS_VERIFY=no&lt;/P&gt;&lt;P&gt;SC4S_DEST_SPLUNK_HEC_TLS_CA_FILE=/etc/ssl/certs/ca-certificates.crt&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_TLS_CLIENT_CERT=/etc/syslog-ng/tls/splunk.crt&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_TLS_CLIENT_KEY=/etc/syslog-ng/tls/splunk.key&lt;/P&gt;&lt;P&gt;SC4S_SOURCE_TLS_ENABLE=yes&lt;BR /&gt;SC4S_SOURCE_TLS_KEY=/etc/syslog-ng/tls/server.key&lt;BR /&gt;SC4S_SOURCE_TLS_CERT=/etc/syslog-ng/tls/server.pem&lt;/P&gt;&lt;P&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_DISKBUFF_ENABLE=yes&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DEFAULT_DISKBUFF_DIR=/var/lib/sc4s/disk-buffer&lt;/P&gt;&lt;P&gt;SC4S_HEALTH_CHECK_ENABLE=true&lt;BR /&gt;SC4S_LISTEN_INTERNAL_HEALTH_PORT=9129&lt;/P&gt;&lt;P&gt;SC4S_ETC=/etc/syslog-ng&lt;/P&gt;&lt;P&gt;SC4S_LISTEN_CHECKPOINT_SPLUNK_NOISE_CONTROL_SECONDS=30&lt;/P&gt;&lt;P&gt;SC4S_LISTEN_STATUS_PORT=9129&lt;BR /&gt;SC4S_LISTEN_DEFAULT_TCP_PORT=41514&lt;BR /&gt;SC4S_LISTEN_DEFAULT_UDP_PORT=42514&lt;BR /&gt;SC4S_LISTEN_DEFAULT_TLS_PORT=7514&lt;BR /&gt;SC4S_LISTEN_DEFAULT_RFC5426_PORT=41601&lt;BR /&gt;SC4S_LISTEN_DEFAULT_RFC6587_PORT=42601&lt;BR /&gt;SC4S_LISTEN_DEFAULT_RFC5425_PORT=7425&lt;/P&gt;&lt;P&gt;SC4S_HEALTH_CHECK_ENABLE=true&lt;/P&gt;&lt;P&gt;SC4S_DEST_SPLUNK_HEC_BATCH_SIZE=1&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_RETRY_LIMIT=1&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_RETRY_INTERVAL=5&lt;/P&gt;&lt;P&gt;SOURCE_ALL_SET=DEFAULT_TCP,DEFAULT_UDP&lt;/P&gt;&lt;P&gt;# SC4S_SEND_METRICS_TERMINAL=no&lt;/P&gt;&lt;P&gt;SC4S_DEBUG=false&lt;BR /&gt;SC4S_LOG_LEVEL=false&lt;BR /&gt;SC4S_DEFAULT_TIMEZONE=Europe/Berlin&lt;BR /&gt;PYTHONPATH=/var/lib/python-venv/lib/python3.12/site-packages:/etc/syslog-ng/python:/etc/syslog-ng/pylib&lt;BR /&gt;# Tunning settings&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_TIME_REOPEN=30&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_BATCH_LINES=100&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_BATCH_TIMEOUT=5000&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_KEEPALIVE=yes&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_WORKERS=8&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DISKBUFF_ENABLE=yes&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DISKBUFF_RELIABLE=yes&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DISKBUFF_MEMBUFLENGTH=10000&lt;BR /&gt;SC4S_DEST_SPLUNK_HEC_DISKBUFF_DISKBUFSIZE=200000000&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 13:57:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/SC4S-to-Splunk-Cloud-forwarding-receiving-errors/m-p/710841#M3543</guid>
      <dc:creator>tigerdice</dc:creator>
      <dc:date>2025-02-06T13:57:58Z</dc:date>
    </item>
  </channel>
</rss>

