<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I getting TcpOutputQ errors in forwarders splunkd.log? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-TcpOutputQ-errors-in-forwarders-splunkd-log/m-p/601689#M104822</link>
    <description>&lt;P&gt;hi Team,&lt;/P&gt;&lt;P&gt;Any updated?&lt;/P&gt;&lt;P&gt;below are the more logs.&lt;/P&gt;&lt;P&gt;(IP's in the below logs are intentionally masked)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;06-11-2022 10:18:11.819 +0000 WARN TcpOutputProc - Possible duplication of events with channel=source::/opt/splunkforwarder/var/log/splunk/health.log|host::XXXXXXXXXXX|splunkd|727, streamId=0, offset=0 on host=xxxxxxxx:9997&lt;BR /&gt;06-11-2022 10:18:11.819 +0000 WARN TcpOutputProc - Possible duplication of events with channel=source::/var/log/cron|host::xxxxxxxxxx|cron|637, streamId=0, offset=0 on host=XXXXXXXXXXXX:9997&lt;BR /&gt;06-11-2022 10:18:11.827 +0000 ERROR TcpOutputQ - Unexpected event id=2&lt;BR /&gt;06-11-2022 10:18:11.829 +0000 INFO TcpOutputProc - Connected to idx=xxxxxxxxxx:9997, pset=0, reuse=0. using ACK.&lt;BR /&gt;06-11-2022 10:18:11.829 +0000 ERROR TcpOutputQ - Unexpected event id=3&lt;BR /&gt;06-11-2022 10:18:11.829 +0000 ERROR TcpOutputQ - Unexpected event id=4&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jun 2022 09:20:55 GMT</pubDate>
    <dc:creator>krishnarajapant</dc:creator>
    <dc:date>2022-06-14T09:20:55Z</dc:date>
    <item>
      <title>Why am I getting TcpOutputQ errors in forwarders splunkd.log?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-TcpOutputQ-errors-in-forwarders-splunkd-log/m-p/601545#M104806</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We are constantly getting below errors in forwarders splukd.log&lt;/P&gt;
&lt;P&gt;ERROR TCPOutputQ - Unexpected event id=4&lt;/P&gt;
&lt;P&gt;ERROR TCPOutputQ - Unexpected event id=7&lt;/P&gt;
&lt;P&gt;However we have observed data is getting ingested to splunkindexers with out any issue. can any one please help us to understand what exactly this error is related to&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With Regards,&lt;/P&gt;
&lt;P&gt;Krishna.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 20:23:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-TcpOutputQ-errors-in-forwarders-splunkd-log/m-p/601545#M104806</guid>
      <dc:creator>krishnarajapant</dc:creator>
      <dc:date>2022-06-13T20:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting TcpOutputQ errors in forwarders splunkd.log?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-TcpOutputQ-errors-in-forwarders-splunkd-log/m-p/601689#M104822</link>
      <description>&lt;P&gt;hi Team,&lt;/P&gt;&lt;P&gt;Any updated?&lt;/P&gt;&lt;P&gt;below are the more logs.&lt;/P&gt;&lt;P&gt;(IP's in the below logs are intentionally masked)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;06-11-2022 10:18:11.819 +0000 WARN TcpOutputProc - Possible duplication of events with channel=source::/opt/splunkforwarder/var/log/splunk/health.log|host::XXXXXXXXXXX|splunkd|727, streamId=0, offset=0 on host=xxxxxxxx:9997&lt;BR /&gt;06-11-2022 10:18:11.819 +0000 WARN TcpOutputProc - Possible duplication of events with channel=source::/var/log/cron|host::xxxxxxxxxx|cron|637, streamId=0, offset=0 on host=XXXXXXXXXXXX:9997&lt;BR /&gt;06-11-2022 10:18:11.827 +0000 ERROR TcpOutputQ - Unexpected event id=2&lt;BR /&gt;06-11-2022 10:18:11.829 +0000 INFO TcpOutputProc - Connected to idx=xxxxxxxxxx:9997, pset=0, reuse=0. using ACK.&lt;BR /&gt;06-11-2022 10:18:11.829 +0000 ERROR TcpOutputQ - Unexpected event id=3&lt;BR /&gt;06-11-2022 10:18:11.829 +0000 ERROR TcpOutputQ - Unexpected event id=4&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 09:20:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-TcpOutputQ-errors-in-forwarders-splunkd-log/m-p/601689#M104822</guid>
      <dc:creator>krishnarajapant</dc:creator>
      <dc:date>2022-06-14T09:20:55Z</dc:date>
    </item>
  </channel>
</rss>

