<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why this error  after upgrade to 9.0 &amp;quot;ERROR TcpOutputQ [&amp;lt;thread id&amp;gt; TcpOutEloop] - Unexpected event id=&amp;amp;l in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/616083#M106461</link>
    <description>&lt;P&gt;If the issue is fixed in 9.0.1, why am I getting the same error message in Splunk 9.0.1?&lt;/P&gt;&lt;P&gt;ERROR TcpOutputQ [&amp;lt;id&amp;gt; TcpOutEloop] - Unexpected eventid=&amp;lt;id&amp;gt;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Oct 2022 05:05:49 GMT</pubDate>
    <dc:creator>Sithima</dc:creator>
    <dc:date>2022-10-06T05:05:49Z</dc:date>
    <item>
      <title>Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&lt;eventid&gt;"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/604790#M105160</link>
      <description>&lt;P&gt;After upgrade to 9.0 seeing following&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR TcpOutputQ [&amp;lt;thread id&amp;gt; TcpOutEloop] - Unexpected event id=&amp;lt;eventid&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jul 2022 16:46:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/604790#M105160</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2022-07-09T16:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;l</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/604794#M105161</link>
      <description>&lt;P&gt;If useACK set to true and batch mode is on(default on) with Splunk 9.0, there is a possibility of hitting following error log messages.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Unexpected event id"&lt;BR /&gt;"Invalid ACK received from indexer"&lt;BR /&gt;"Got unexpected ACK with eventid"&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;This may also lead to blocked queues on forwarding tier.&lt;/P&gt;&lt;P&gt;autoLBVolume and autoBatch while processing an event, apply limit using raw size of the event. However if there are&amp;nbsp; raw less events ( e.g. metrics events) autoLBVolume and autoBatch will end up sending lot more events then configured limits to receiver.&lt;BR /&gt;With&amp;nbsp;autoLBVolume, it results in more than expected/configured events distributed to receivers.&lt;/P&gt;&lt;P&gt;With autoBatch, it results in batch of lot more events than expected. That means while a batch of thousands of events being sent to receiver, at the same time some events are already getting acknowledged.&lt;BR /&gt;Forwarder creates a list of&amp;nbsp;&amp;nbsp;&lt;EM&gt;&lt;U&gt;events to be acknowledged&lt;/U&gt;&lt;/EM&gt; after successfully sending batch of events. However if the batch is in-flight over TCP layer and forwarder receives an ACKed event of the batch, it's not in the list of expected&amp;nbsp;&lt;EM&gt;&lt;U&gt;events to be acknowledged.&amp;nbsp;&lt;/U&gt;&lt;/EM&gt; That leads to above ERROR.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Workaround: Either set useACK=false or autoBatch=false&lt;/P&gt;&lt;P&gt;Issue is fixed by 9.0.3 patch.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note:&amp;nbsp;&lt;BR /&gt;&lt;/STRONG&gt;After 9.0.3 upgrade, you will still see&amp;nbsp;&lt;SPAN&gt;benign&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;“Unexpected event id”&lt;/STRONG&gt; log message. However there should not be following log messages.&lt;BR /&gt;&lt;STRONG&gt;"Invalid ACK received from indexer"&lt;BR /&gt;"Got unexpected ACK with eventid"&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 04:07:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/604794#M105161</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2023-01-18T04:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;l</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/605753#M105298</link>
      <description>&lt;P&gt;It helps Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 09:04:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/605753#M105298</guid>
      <dc:creator>vinayakwagh</dc:creator>
      <dc:date>2022-07-15T09:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;l</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/616083#M106461</link>
      <description>&lt;P&gt;If the issue is fixed in 9.0.1, why am I getting the same error message in Splunk 9.0.1?&lt;/P&gt;&lt;P&gt;ERROR TcpOutputQ [&amp;lt;id&amp;gt; TcpOutEloop] - Unexpected eventid=&amp;lt;id&amp;gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 05:05:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/616083#M106461</guid>
      <dc:creator>Sithima</dc:creator>
      <dc:date>2022-10-06T05:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/616171#M106468</link>
      <description>&lt;P&gt;9.0.1 has not suppressed the ERROR log. It fixes the underlying tcpout queue blockage&amp;nbsp; issue. While you see the ERROR log but no tcpout queue blockage (as seen with 9.0.0) is an indication that the&amp;nbsp;tcpout queue blockage&amp;nbsp; issue is resolved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will suppress 9.0.1&amp;nbsp;benign ERROR log in future releases.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 12:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/616171#M106468</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2022-10-06T12:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;l</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/619135#M106768</link>
      <description>&lt;P&gt;It is back in v9.0.1&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 15:05:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/619135#M106768</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2022-11-01T15:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/619137#M106769</link>
      <description>&lt;P&gt;See my updated answer. 9.0.1 still logs the ERROR, but it does not block forwarder.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 15:17:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/619137#M106769</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2022-11-01T15:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/619191#M106773</link>
      <description>&lt;P&gt;Actually the problem is still there.&amp;nbsp; I was getting continuous crashes on my HWF.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 18:36:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/619191#M106773</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2022-11-01T18:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/619192#M106774</link>
      <description>&lt;P&gt;That crash is still an issue and will be fixed.&amp;nbsp; It happens if&amp;nbsp;&lt;STRONG&gt;forceTimebasedAutoLB=true&lt;/STRONG&gt;&lt;BR /&gt;Workaround for 9.0.1 TcpOutputQ crash&amp;nbsp;&lt;BR /&gt;Set one of the following&lt;/P&gt;&lt;PRE&gt;forceTimebasedAutoLB=false&lt;/PRE&gt;&lt;P&gt;or&lt;/P&gt;&lt;PRE&gt;autoBatch=false&lt;/PRE&gt;&lt;P&gt;or&lt;/P&gt;&lt;PRE&gt;connectionsPerTarget=1&lt;/PRE&gt;&lt;P&gt;This crash is applicable if UF/HF resolves &amp;lt; 10 target IP addresses and&amp;nbsp;&lt;STRONG&gt;forceTimebasedAutoLB=true.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 19:22:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/619192#M106774</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2022-11-01T19:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/672592#M112667</link>
      <description>&lt;P&gt;The issue is not fixed&amp;nbsp;after upgrading 9.1.2. This issue occured on search head cluster.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My settings in outputs.conf :&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[indexer_discovery:target_master]
pass4SymmKey = **********

[tcpout]
defaultGroup = default_indexers
forceTimebasedAutoLB = true
maxQueueSize = 7MB
useACK = true

[tcpout:default_indexers]
server = **********01:9997,**********02.lan:9997
&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 15:04:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/672592#M112667</guid>
      <dc:creator>pmerlin1</dc:creator>
      <dc:date>2023-12-22T15:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/672609#M112673</link>
      <description>&lt;P&gt;It needs to be&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;UseAck = false&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then this errors should resolve.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 15:04:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/672609#M112673</guid>
      <dc:creator>Vwagh</dc:creator>
      <dc:date>2023-12-22T15:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/672634#M112682</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Following three logs&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Unexpected event id" ( 9.1.2 still logs)&lt;BR /&gt;"Invalid ACK received from indexer"&amp;nbsp;( 9.1.2 should not log)&lt;BR /&gt;"Got unexpected ACK with eventid" (9.1.2 should not log)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;What exactly the issue you are hitting?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 21:10:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/672634#M112682</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2023-12-22T21:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;l</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/676961#M113214</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206899"&gt;@lawrence_magpoc&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I am running with Splunk Universal Forwarder 9.0.2 in one of my Linux client machine and recently for the past couple of days i am getting this events in the internal logs and it seems like its getting crashed and once again the service is getting started automatically.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;build&lt;/SPAN&gt; &lt;SPAN class=""&gt;17e00c557dc1&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;2024-02-08&lt;/SPAN&gt; &lt;SPAN class=""&gt;05:26:15&lt;/SPAN&gt; &lt;SPAN class=""&gt;Received&lt;/SPAN&gt; &lt;SPAN class=""&gt;fatal&lt;/SPAN&gt; &lt;SPAN class=""&gt;signal&lt;/SPAN&gt; &lt;SPAN class=""&gt;6&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;Aborted&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;PID&lt;/SPAN&gt; &lt;SPAN class=""&gt;1908113.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Cause:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Signal&lt;/SPAN&gt; &lt;SPAN class=""&gt;sent&lt;/SPAN&gt; &lt;SPAN class=""&gt;by&lt;/SPAN&gt; &lt;SPAN class=""&gt;PID&lt;/SPAN&gt; &lt;SPAN class=""&gt;1908113&lt;/SPAN&gt; &lt;SPAN class=""&gt;running&lt;/SPAN&gt; &lt;SPAN class=""&gt;under&lt;/SPAN&gt; &lt;SPAN class=""&gt;UID&lt;/SPAN&gt; &lt;SPAN class=""&gt;9991.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Crashing&lt;/SPAN&gt; &lt;SPAN class=""&gt;thread:&lt;/SPAN&gt; &lt;SPAN class=""&gt;TcpOutEloop&lt;/SPAN&gt; &lt;SPAN class=""&gt;Registers:&lt;/SPAN&gt; &lt;SPAN class=""&gt;RIP:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;0x00007F65EB39AACF&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;gsignal&lt;/SPAN&gt;&lt;SPAN&gt; + &lt;/SPAN&gt;&lt;SPAN class=""&gt;271&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;libc.so.6&lt;/SPAN&gt;&lt;SPAN&gt; + &lt;/SPAN&gt;&lt;SPAN class=""&gt;0x4EACF&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class=""&gt;TcpOutputQ&lt;/SPAN&gt; [&lt;SPAN class=""&gt;1908232&lt;/SPAN&gt; &lt;SPAN class=""&gt;TcpOutEloop&lt;/SPAN&gt;] &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Unexpected&lt;/SPAN&gt; &lt;SPAN class=""&gt;event&lt;/SPAN&gt; &lt;SPAN class=""&gt;id=30&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;ERROR TcpOutputQ [1908232 TcpOutEloop] - Unexpected event id=29&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;So how to fix this issue and also in which config file we need to add in the client machine where UF is running.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;autoBatch=false&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 12:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/676961#M113214</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2024-02-08T12:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/676963#M113215</link>
      <description>&lt;P&gt;In outputs.conf set&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;useACK=false

autoBatch=false&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 08 Feb 2024 13:09:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/676963#M113215</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2024-02-08T13:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/676972#M113216</link>
      <description>&lt;PRE&gt;useACK = &amp;lt;boolean&amp;gt;
* Whether or not to use indexer acknowledgment.
* Indexer acknowledgment is an optional capability on forwarders that helps
  prevent loss of data when sending data to an indexer.&lt;/PRE&gt;&lt;P&gt;the workaround means you don't need use the indexer aknowledgment, so you run the risk of losing data during an indexer restart. The solution is not suitable for me.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 15:37:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/676972#M113216</guid>
      <dc:creator>pmerlin1</dc:creator>
      <dc:date>2024-02-08T15:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/676973#M113217</link>
      <description>&lt;P&gt;Upgrade to 9.0.3 and above.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 15:44:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/676973#M113217</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2024-02-08T15:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/677034#M113225</link>
      <description>&lt;P&gt;The message appeared for forwarders (search head cluster) upgraded in 9.1.2&lt;/P&gt;&lt;P&gt;settings:&amp;nbsp;&lt;/P&gt;&lt;P&gt;forceTimebasedAutoLB = false&lt;/P&gt;&lt;P&gt;useACK = true&lt;/P&gt;&lt;P&gt;autoLBFrequency = 30&lt;/P&gt;&lt;P&gt;Upgrading don't change the behavior on full enterprise splunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this seems to work on Universal Forwarder&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 07:50:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/677034#M113225</guid>
      <dc:creator>pmerlin1</dc:creator>
      <dc:date>2024-02-09T07:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/677150#M113230</link>
      <description>&lt;P&gt;Can you let us know which log you see?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Following three logs&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Unexpected event id" ( 9.1.2 still logs)&lt;BR /&gt;"Invalid ACK received from indexer"&amp;nbsp;( 9.1.2 should not log)&lt;BR /&gt;"Got unexpected ACK with eventid" (9.1.2 should not log)&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 17:12:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/677150#M113230</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2024-02-09T17:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/677302#M113247</link>
      <description>&lt;P&gt;&lt;STRONG&gt;The message still logged is :&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;"Unexpected event id"&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 15:57:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/677302#M113247</guid>
      <dc:creator>pmerlin1</dc:creator>
      <dc:date>2024-02-12T15:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error  after upgrade to 9.0 "ERROR TcpOutputQ [&lt;thread id&gt; TcpOutEloop] - Unexpected event id=&amp;a</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/677559#M113275</link>
      <description>&lt;P&gt;This is expected and benign ERROR. We will change log to INFO in future.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 13:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-this-error-after-upgrade-to-9-0-quot-ERROR-TcpOutputQ-lt/m-p/677559#M113275</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2024-02-14T13:34:42Z</dc:date>
    </item>
  </channel>
</rss>

