<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FwdDataReceiverThread error | Read Timeout Timed out after 600 seconds in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628258#M107836</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes, they work on the same machine. Syslog server writes logs to the filesystem, on the same machine HF or UF will use monitor input to ingest the data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2023 10:41:06 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2023-01-25T10:41:06Z</dc:date>
    <item>
      <title>FwdDataReceiverThread error | Read Timeout Timed out after 600 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628233#M107824</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;&lt;P&gt;I the following error on my Splunk HF which is listening to incoming data from F5 network appliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;01-25-2023 08:06:56.794 +0000 ERROR TcpInputProc [2612981 FwdDataReceiverThread] - Error encountered for connection from src=&amp;lt;internal_ip_f5&amp;gt;:59697. Read Timeout Timed out after 600 seconds.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am wondering what the number after the F5 IP is... I specified a unique port for the forwarding of data between f5 and the HF so I do not understand why I have number like&amp;nbsp;59697 (and many others).&lt;/P&gt;&lt;P&gt;More generally I do not know how to troubleshoot this...&lt;/P&gt;&lt;P&gt;Thanks for your help,&lt;/P&gt;&lt;P&gt;GaetanVP&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 08:26:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628233#M107824</guid>
      <dc:creator>GaetanVP</dc:creator>
      <dc:date>2023-01-25T08:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: FwdDataReceiverThread error | Read Timeout Timed out after 600 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628235#M107826</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;TcpInputProc logs show the connection source in &amp;lt;src_ip_address&amp;gt;:&amp;lt;src_port&amp;gt; format.&amp;nbsp;&lt;SPAN&gt;59697 is the source port of your F5 device. Since it is retrying to connect HF to send data, this source port changes every time.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 08:30:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628235#M107826</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2023-01-25T08:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: FwdDataReceiverThread error | Read Timeout Timed out after 600 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628241#M107829</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;, thanks but I am not sure to understand&lt;/P&gt;&lt;P&gt;How does the src port impact the data flow ?&lt;BR /&gt;I configured f5 to forward data to a specific port on&amp;nbsp; the HF, and I configured the HF to listen on that port.&lt;/P&gt;&lt;P&gt;Why would F5 retry to connect to HF with a different source port ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 09:08:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628241#M107829</guid>
      <dc:creator>GaetanVP</dc:creator>
      <dc:date>2023-01-25T09:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: FwdDataReceiverThread error | Read Timeout Timed out after 600 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628243#M107830</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Let's assume you configured HF to listen TCP 5140 port and configured F5 to send to TCP 5140. F5 connects to HF TCP5140 but since TCP connections have both source and destination ports, F5 randomly needs to assign a source port for this connection (&lt;SPAN&gt;59697&lt;/SPAN&gt;), which you see in the log files. It does not mean it is trying to connect to this&amp;nbsp;&lt;SPAN&gt;59697 port. This log is only for debugging inside firewall logs etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Listening directly TCP ports on Splunk is not recommended. Most probably your HF is having performance problems or cannot process data as fast as needed. At that time F5 detects that blocking and tries to restart the connection.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The best practice is using a Syslog server &amp;nbsp;(Rsylog or SyslogNG) to listen to TCP/UDP ports and writes to a file, HF monitors this file and ingests data.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You can see below links for further information&lt;/P&gt;&lt;P&gt;&lt;A href="https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about.pdf" target="_blank"&gt;https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Or you can use Splunk Connect for Syslog&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/main/faq/" target="_blank"&gt;https://splunk.github.io/splunk-connect-for-syslog/main/faq/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 09:35:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628243#M107830</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2023-01-25T09:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: FwdDataReceiverThread error | Read Timeout Timed out after 600 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628257#M107835</link>
      <description>&lt;P&gt;Thanks for all those info !&lt;/P&gt;&lt;P&gt;One last question, when you mentioned "&lt;SPAN&gt;&amp;nbsp;Syslog server &amp;nbsp;(Rsylog or SyslogNG) to listen to TCP/UDP ports and writes to a file, HF monitors this file and ingests data"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does the HF and the Syslog server would be on the same machine ?&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 10:36:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628257#M107835</guid>
      <dc:creator>GaetanVP</dc:creator>
      <dc:date>2023-01-25T10:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: FwdDataReceiverThread error | Read Timeout Timed out after 600 seconds</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628258#M107836</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes, they work on the same machine. Syslog server writes logs to the filesystem, on the same machine HF or UF will use monitor input to ingest the data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 10:41:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FwdDataReceiverThread-error-Read-Timeout-Timed-out-after-600/m-p/628258#M107836</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2023-01-25T10:41:06Z</dc:date>
    </item>
  </channel>
</rss>

