<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ERROR TcpOutputFd - Read error. Connection reset by peer : splunkforwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/640062#M109260</link>
    <description>&lt;P&gt;I tried to disable FIPS on Splunk forwarder as it looks like FIPS is disabled on Splunk cloud or indexer also any forwarder with FIPS turned on will fail to be allowed to connect.&lt;BR /&gt;&lt;BR /&gt;On the mis-configured forwarders disable FIPS and reboot.&lt;BR /&gt;&lt;BR /&gt;Check FIPS is disabled with the next command:&lt;BR /&gt;&lt;BR /&gt;cat /proc/sys/crypto/fips_enabled 0&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.splunk.com_Documentation_Splunk_8.0.3_Security_SecuringSplunkEnterprisewithFIPS&amp;amp;d=DwMFAw&amp;amp;c=eIGjsITfXP_y-DLLX0uEHXJvU8nOHrUK8IrwNKOtkVU&amp;amp;r=VXrdxW4sbc9k3lJiE3gPPIWJRTJmcOtQp6puPTbZ0Eg&amp;amp;m=yiZFShJ-OwMbD95g9lv_EpKpRL8G0qC1f43P3sj4-DyOVuK19OrAJ2exKT8Iy4tx&amp;amp;s=4faraU5ED94iZdDemMcIYlWMuj30ufR_6BBjNULzhQk&amp;amp;e=" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Security/SecuringSplunkEnterprisewithFIPS&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The Federal Information Processing Standard (FIPS) uses government-certified versions of some algorithms to meet regulatory guidelines.&lt;BR /&gt;It should not be considered a security enhancement by itself, and might potentially reduce performance on your system.&lt;BR /&gt;Enable FIPS if it is a regulatory requirement for your environment.&lt;BR /&gt;Splunk Enterprise and the Universal Forwarder use an embedded FIPS 140-2-validated cryptographic module.&lt;BR /&gt;Thus you need FIPS enabled and running on both the Forwarder side and the Indexer side&lt;/P&gt;</description>
    <pubDate>Sat, 15 Apr 2023 06:11:09 GMT</pubDate>
    <dc:creator>sraymondg</dc:creator>
    <dc:date>2023-04-15T06:11:09Z</dc:date>
    <item>
      <title>ERROR TcpOutputFd - Read error. Connection reset by peer : splunkforwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/242723#M47055</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;I am pretty much new to Splunk. I want to forward audit.log of one of my Linux servers to view in Splunk Web. For this, I did the following steps:&lt;/P&gt;

&lt;P&gt;1) Upgraded version of splunkforwarder to 6.4.2&lt;BR /&gt;
2) Modified inputs.conf and outputs.conf &lt;BR /&gt;
3) Restarted Splunk&lt;/P&gt;

&lt;P&gt;But i am getting below logs in splunkd.log. Please let me know how to see these audit.logs in Splunk Web. Am I missing any steps?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;08-23-2016 10:37:56.325 +0000 INFO  WatchedFile - Will begin reading at offset=5111808 for file='/opt/zenoss/log/audit.log'.
08-23-2016 10:37:56.626 +0000 ERROR TcpOutputFd - Read error. Connection reset by peer
08-23-2016 10:38:03.020 +0000 INFO  TailReader - Could not send data to output queue (parsingQueue), retrying...
08-23-2016 10:38:03.020 +0000 INFO  TailReader - Could not send data to output queue (parsingQueue), retrying...
08-23-2016 10:38:26.227 +0000 ERROR TcpOutputProc - Can't find or illegal IP address or Name: NONE
08-23-2016 10:38:26.228 +0000 ERROR TcpOutputFd - Read error. Connection reset by peer
08-23-2016 10:38:56.231 +0000 ERROR TcpOutputFd - Read error. Connection reset by peer
08-23-2016 10:39:26.235 +0000 ERROR TcpOutputFd - Read error. Connection reset by peer
08-23-2016 10:39:38.909 +0000 WARN  TcpOutputProc - Forwarding to indexer group splunkcloud blocked for 100 seconds.
08-23-2016 10:39:56.227 +0000 ERROR TcpOutputFd - Read error. Connection reset by peer
08-23-2016 10:40:26.227 +0000 ERROR TcpOutputFd - Read error. Connection reset by peer
08-23-2016 10:40:56.216 +0000 ERROR TcpOutputFd - Read error. Connection reset by peer
08-23-2016 10:41:18.525 +0000 WARN  TcpOutputProc - Forwarding to indexer group splunkcloud blocked for 200 seconds.
08-23-2016 10:41:26.211 +0000 ERROR TcpOutputFd - Read error. Connection reset by peer
08-23-2016 10:41:56.198 +0000 ERROR TcpOutputFd - Read error. Connection reset by peer
08-23-2016 10:42:26.200 +0000 ERROR TcpOutputFd - Read error. Connection reset by peer
08-23-2016 10:42:56.200 +0000 ERROR TcpOutputFd - Read error. Connection reset by peer
08-23-2016 10:42:58.896 +0000 WARN  TcpOutputProc - Forwarding to indexer group splunkcloud blocked for 300 seconds.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Please help&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2016 10:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/242723#M47055</guid>
      <dc:creator>sanaa</dc:creator>
      <dc:date>2016-08-23T10:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputFd - Read error. Connection reset by peer : splunkforwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/242724#M47056</link>
      <description>&lt;P&gt;Check your indexer version .. indexer should be high or equal version.. if not here are the few steps to troubleshoot,&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;check your outputs.conf  - &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;indexer ip  - wrong ips  / firewall issue&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;telnet the indexer ip from forwarder and check the connection is valid or not? use the below &lt;BR /&gt;
     telnet &lt;IP&gt; &lt;PORT&gt;&lt;BR /&gt;&lt;BR /&gt;
     eg:&lt;/PORT&gt;&lt;/IP&gt;&lt;/P&gt;

&lt;P&gt;telnet 10.99.0.1 9997&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;hope this will helps you.&lt;/P&gt;

&lt;P&gt;thanks,&lt;BR /&gt;
V&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2016 19:55:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/242724#M47056</guid>
      <dc:creator>vasanthmss</dc:creator>
      <dc:date>2016-08-23T19:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputFd - Read error. Connection reset by peer : splunkforwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/536844#M89988</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/51948"&gt;@vasanthmss&lt;/a&gt;&amp;nbsp;Do you have any other suggestions?&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are working on Splunk 7.2.9.1. but encountered similar issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ERROR TcpOutputFd - Read error. Connection reset by peer&lt;/EM&gt; occured on one indexer. Splunkd stopped.&lt;/P&gt;&lt;P&gt;Then Splunk stopped on other 3 indexers that ended up with the following errors:&lt;BR /&gt;&lt;EM&gt;ERROR TcpOutputFd - Connection to host=xyzf failed&amp;nbsp;&lt;/EM&gt;and&amp;nbsp;&lt;BR /&gt;&lt;EM&gt;ERROR TcpOutputFd - Connect to host=xyzf refused.&amp;nbsp;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Also, in the same timeframe there was &lt;EM&gt;ClusterSlaveBucketHandler ERROR &lt;/EM&gt;on one of the indexers.&lt;/P&gt;&lt;P&gt;Splunk version for all indexers is the same. I checked outputs.conf and run telnet between indexers. All fine.&lt;/P&gt;&lt;P&gt;Any hints will be much appreciated!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 14:56:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/536844#M89988</guid>
      <dc:creator>justynap_ldz</dc:creator>
      <dc:date>2021-01-22T14:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputFd - Read error. Connection reset by peer : splunkforwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/622423#M107149</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am having the same issue.&lt;/P&gt;&lt;P&gt;Logs are not going to index from forwarder and I am getting same error.&lt;/P&gt;&lt;P&gt;Did you got any solution for this?&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225278"&gt;@justynap_ldz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 14:14:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/622423#M107149</guid>
      <dc:creator>Sanjayr1081</dc:creator>
      <dc:date>2022-11-29T14:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputFd - Read error. Connection reset by peer : splunkforwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/640062#M109260</link>
      <description>&lt;P&gt;I tried to disable FIPS on Splunk forwarder as it looks like FIPS is disabled on Splunk cloud or indexer also any forwarder with FIPS turned on will fail to be allowed to connect.&lt;BR /&gt;&lt;BR /&gt;On the mis-configured forwarders disable FIPS and reboot.&lt;BR /&gt;&lt;BR /&gt;Check FIPS is disabled with the next command:&lt;BR /&gt;&lt;BR /&gt;cat /proc/sys/crypto/fips_enabled 0&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.splunk.com_Documentation_Splunk_8.0.3_Security_SecuringSplunkEnterprisewithFIPS&amp;amp;d=DwMFAw&amp;amp;c=eIGjsITfXP_y-DLLX0uEHXJvU8nOHrUK8IrwNKOtkVU&amp;amp;r=VXrdxW4sbc9k3lJiE3gPPIWJRTJmcOtQp6puPTbZ0Eg&amp;amp;m=yiZFShJ-OwMbD95g9lv_EpKpRL8G0qC1f43P3sj4-DyOVuK19OrAJ2exKT8Iy4tx&amp;amp;s=4faraU5ED94iZdDemMcIYlWMuj30ufR_6BBjNULzhQk&amp;amp;e=" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Security/SecuringSplunkEnterprisewithFIPS&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The Federal Information Processing Standard (FIPS) uses government-certified versions of some algorithms to meet regulatory guidelines.&lt;BR /&gt;It should not be considered a security enhancement by itself, and might potentially reduce performance on your system.&lt;BR /&gt;Enable FIPS if it is a regulatory requirement for your environment.&lt;BR /&gt;Splunk Enterprise and the Universal Forwarder use an embedded FIPS 140-2-validated cryptographic module.&lt;BR /&gt;Thus you need FIPS enabled and running on both the Forwarder side and the Indexer side&lt;/P&gt;</description>
      <pubDate>Sat, 15 Apr 2023 06:11:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/640062#M109260</guid>
      <dc:creator>sraymondg</dc:creator>
      <dc:date>2023-04-15T06:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputFd - Read error. Connection reset by peer : splunkforwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/640134#M109273</link>
      <description>&lt;P&gt;Here are some things that hopefully you can change/disable that can get in the way:&lt;BR /&gt;FIPS&lt;BR /&gt;selinux&lt;BR /&gt;firewall (firewalld)&lt;BR /&gt;missing route&lt;BR /&gt;dns&lt;/P&gt;</description>
      <pubDate>Sun, 16 Apr 2023 20:45:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpOutputFd-Read-error-Connection-reset-by-peer/m-p/640134#M109273</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-04-16T20:45:16Z</dc:date>
    </item>
  </channel>
</rss>

