<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After Upgrade from Splunk 7.2.3 to Splunk 8.0.1 we get error TcpInputProc - Encountered Streaming S2S error=Received reference to unknown channel_code=132 in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495169#M2906</link>
    <description>&lt;P&gt;Hi, this was be solved on my environment by applying the below config on outputs.conf on your HeavyForwarder.&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
negotiateProtocolLevel = 0&lt;/P&gt;

&lt;P&gt;Once applied, you need to restart splunk service.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2020 01:24:54 GMT</pubDate>
    <dc:creator>jhomerlopez</dc:creator>
    <dc:date>2020-02-11T01:24:54Z</dc:date>
    <item>
      <title>After Upgrade from Splunk 7.2.3 to Splunk 8.0.1 we get error TcpInputProc - Encountered Streaming S2S error=Received reference to unknown channel_code=132</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495168#M2905</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am dealing with an issue where after upgrading our Splunk environment from 7.2.3 to 8.0.1 we are having endless errrors as stated in the title on the indexers within the cluster.&lt;BR /&gt;
&lt;STRONG&gt;Error - 01-23-2020 15:58:09.056 +0200 ERROR TcpInputProc - Encountered Streaming S2S error=Received reference to unknown channel_code=132 for data received from src=1&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Data flow is - UF --&amp;gt; Heavy Forwarder --&amp;gt; Indexer&lt;/P&gt;

&lt;P&gt;Anyone that can shed some light on this?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 14:37:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495168#M2905</guid>
      <dc:creator>QuintonS</dc:creator>
      <dc:date>2020-01-23T14:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade from Splunk 7.2.3 to Splunk 8.0.1 we get error TcpInputProc - Encountered Streaming S2S error=Received reference to unknown channel_code=132</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495169#M2906</link>
      <description>&lt;P&gt;Hi, this was be solved on my environment by applying the below config on outputs.conf on your HeavyForwarder.&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
negotiateProtocolLevel = 0&lt;/P&gt;

&lt;P&gt;Once applied, you need to restart splunk service.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 01:24:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495169#M2906</guid>
      <dc:creator>jhomerlopez</dc:creator>
      <dc:date>2020-02-11T01:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade from Splunk 7.2.3 to Splunk 8.0.1 we get error TcpInputProc - Encountered Streaming S2S error=Received reference to unknown channel_code=132</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495170#M2907</link>
      <description>&lt;P&gt;In the Heavy Forwarders, You have to go to $SPLUNK_HOME/etc/system/local/Outputs.conf and add the value "negotiateProtocolLevel = 0" under the stanza [tcpout] then restart Splunk service. &lt;/P&gt;

&lt;P&gt;After you add that value in the configuration file, Splunk will start to use the old protocol to connect with indexers and the connection should be established again.&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
negotiateProtocolLevel = 0&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 04:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495170#M2907</guid>
      <dc:creator>yaasirvatham_sp</dc:creator>
      <dc:date>2020-02-11T04:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade from Splunk 7.2.3 to Splunk 8.0.1 we get error TcpInputProc - Encountered Streaming S2S error=Received reference to unknown channel_code=132</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495171#M2908</link>
      <description>&lt;P&gt;Thank you for the response, this solved my issue. Just another question is this only for the Heavy Forwarder to indexer or would it also be applicable from UF to Heavy Forwarder?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 06:21:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495171#M2908</guid>
      <dc:creator>QuintonS</dc:creator>
      <dc:date>2020-02-11T06:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade from Splunk 7.2.3 to Splunk 8.0.1 we get error TcpInputProc - Encountered Streaming S2S error=Received reference to unknown channel_code=132</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495172#M2909</link>
      <description>&lt;P&gt;Thank you for the response, this solved my issue. Just another question is this only for the Heavy Forwarder to indexer or would it also be applicable from UF to Heavy Forwarder?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 06:27:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495172#M2909</guid>
      <dc:creator>QuintonS</dc:creator>
      <dc:date>2020-02-11T06:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade from Splunk 7.2.3 to Splunk 8.0.1 we get error TcpInputProc - Encountered Streaming S2S error=Received reference to unknown channel_code=132</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495173#M2910</link>
      <description>&lt;P&gt;I am asking since the Heavy Forwarders have also been upgraded to 8.0.1 but the UF's are still running 7.2.3 and are in the process of being upgraded.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 06:33:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495173#M2910</guid>
      <dc:creator>QuintonS</dc:creator>
      <dc:date>2020-02-11T06:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade from Splunk 7.2.3 to Splunk 8.0.1 we get error TcpInputProc - Encountered Streaming S2S error=Received reference to unknown channel_code=132</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495174#M2911</link>
      <description>&lt;P&gt;My Heavy Forwarders and Indexers are at version 8.0.2 and I still get the error. Why should we set the negotiateProtocolLevel to 0, if both servers (HF &amp;amp; Indexer) are already at the newest version?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:53:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495174#M2911</guid>
      <dc:creator>andreasz</dc:creator>
      <dc:date>2020-02-21T14:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade from Splunk 7.2.3 to Splunk 8.0.1 we get error TcpInputProc - Encountered Streaming S2S error=Received reference to unknown channel_code=132</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495175#M2912</link>
      <description>&lt;P&gt;Support confirmed that this is a bug (SPL-182112) for S2S communication between 8.x nodes. In my case I had issues between SH and INX. The recommendation was to set negotiateProtocolLevel=5 to downgrade the protocol version to 7.3. This can be done in the [tcpout] stanza on the sending node (SH), or in the [splunktcp] stanza on the receiving end (INX).&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 09:40:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/495175#M2912</guid>
      <dc:creator>arcsight_guru</dc:creator>
      <dc:date>2020-02-27T09:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade from Splunk 7.2.3 to Splunk 8.0.1 we get error TcpInputProc - Encountered Streaming S2S error=Received</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/677005#M18626</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;The correct workaround should have been&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[tcpout]
negotiateProtocolLevel = 5&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;negotiateProtocolLevel = 0 is no longer valid (see&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;enableOldS2SProtocol in 9.1.x outputs.conf)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;with 9.1.x and is likely to cause issues.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 20:25:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-Upgrade-from-Splunk-7-2-3-to-Splunk-8-0-1-we-get-error/m-p/677005#M18626</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2024-02-08T20:25:11Z</dc:date>
    </item>
  </channel>
</rss>

