<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Forwarder Connection Issue with &amp;quot;Error in SSL_read - sock_error = 10054&amp;quot; in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Forwarder-Connection-Issue-with-quot-Error-in-SSL-read/m-p/419412#M14944</link>
    <description>&lt;P&gt;Not really, the issue persists. &lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2019 06:19:42 GMT</pubDate>
    <dc:creator>caglabaylan</dc:creator>
    <dc:date>2019-08-28T06:19:42Z</dc:date>
    <item>
      <title>Splunk Forwarder Connection Issue with "Error in SSL_read - sock_error = 10054"</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Forwarder-Connection-Issue-with-quot-Error-in-SSL-read/m-p/419410#M14942</link>
      <description>&lt;P&gt;Splunk Forwarder 7.2.1 is installed on Windows 2016 instance cannot send logs/data to the indexer with version 7.1.3.&lt;BR /&gt;
We have other Windows 2008 instances  with same configuration, which can succesfully connect to the indexer. &lt;BR /&gt;
We think that there is a bug with Splunk Forwarder on Windows 2016 instances.&lt;BR /&gt;
(Firewall rules are checked and enabled.)&lt;BR /&gt;
Here are the errors:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-16-2019 13:46:14.222 +0000 INFO  TcpOutputProc - Connection to x.x.x.x:9997 closed. sock_error =
10054. SSL Error = error:00000000:lib(0):func(0):reason(0)

04-16-2019 13:46:14.222 +0000 WARN  TcpOutputProc - Possible duplication of events with channel=source::Perfmon:Process|host::XXXX|Perfmon:Process|, streamId=15911254072694239019, offset=8243074 on host=x.x.x.x:9997

04-16-2019 13:46:14.268 +0000 INFO  TcpOutputProc - Connection to x.x.x.x:9997 closed. default Error in SSL_read = 10054, SSL Error = error:00000000:lib(0):func(0):reason(0)

04-16-2019 13:46:14.268 +0000 WARN  TcpOutputProc - Applying quarantine to ip=x.x.x.x port=9997
_numberOfFailures=2

04-16-2019 13:46:14.268 +0000 WARN  TcpOutputProc - Possible duplication of events with channel=source::Perfmon:Process|host::XXXX|Perfmon:Process|, streamId=15911254072694239019, offset=11879036 on host=x.x.x.x:9997
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 18 Apr 2019 11:53:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Forwarder-Connection-Issue-with-quot-Error-in-SSL-read/m-p/419410#M14942</guid>
      <dc:creator>caglabaylan</dc:creator>
      <dc:date>2019-04-18T11:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder Connection Issue with "Error in SSL_read - sock_error = 10054"</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Forwarder-Connection-Issue-with-quot-Error-in-SSL-read/m-p/419411#M14943</link>
      <description>&lt;P&gt;Did you ever figure out a solution for this one?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 20:24:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Forwarder-Connection-Issue-with-quot-Error-in-SSL-read/m-p/419411#M14943</guid>
      <dc:creator>imarks005</dc:creator>
      <dc:date>2019-08-27T20:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder Connection Issue with "Error in SSL_read - sock_error = 10054"</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Forwarder-Connection-Issue-with-quot-Error-in-SSL-read/m-p/419412#M14944</link>
      <description>&lt;P&gt;Not really, the issue persists. &lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 06:19:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Forwarder-Connection-Issue-with-quot-Error-in-SSL-read/m-p/419412#M14944</guid>
      <dc:creator>caglabaylan</dc:creator>
      <dc:date>2019-08-28T06:19:42Z</dc:date>
    </item>
  </channel>
</rss>

