<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexer Problem: ERROR TcpChannel - Fatal error on accept socket: Software caused connection abort in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Problem-ERROR-TcpChannel-Fatal-error-on-accept-socket/m-p/61919#M12383</link>
    <description>&lt;P&gt;According to Splunk support this Issue wil be fixed in 4.3.1.&lt;BR /&gt;
Apparently the root cause of the problem is, that busy indexers can't send TCP Acks fast enough.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Feb 2012 07:32:00 GMT</pubDate>
    <dc:creator>chris</dc:creator>
    <dc:date>2012-02-02T07:32:00Z</dc:date>
    <item>
      <title>Indexer Problem: ERROR TcpChannel - Fatal error on accept socket: Software caused connection abort</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Problem-ERROR-TcpChannel-Fatal-error-on-accept-socket/m-p/61918#M12382</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;we get the following error message from time to time on our Indexers (Solaris 10 x86 64bit Splunk 4.2.5 or 4.3):&lt;/P&gt;

&lt;P&gt;ERROR TcpChannel - Fatal error on accept socket: Software caused connection abort&lt;/P&gt;

&lt;P&gt;If this occurs netstat shows that the port is still listening:&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
~:netstat -an | grep 99&lt;BR /&gt;
      &lt;EM&gt;.9997               *.&lt;/EM&gt;                0      0 49152      0 LISTEN&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;But i do not get a connection when telneting to the port, the forwarders can't connect to the indexer anymore and it has to be restarted.&lt;/P&gt;

&lt;P&gt;Is there anyone else with the same problem somewhere? Is there a fix for this?&lt;/P&gt;

&lt;P&gt;Thanks for helping &lt;/P&gt;

&lt;P&gt;Chris&lt;/P&gt;

&lt;P&gt;Edit:&lt;BR /&gt;&lt;BR /&gt;
We have downgraded to 4.2.4 on one of our indexers, we haven't had the problem since then. But it has only been running for a couple of hours now. I will update this when more time has passed&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2012 10:32:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Problem-ERROR-TcpChannel-Fatal-error-on-accept-socket/m-p/61918#M12382</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2012-02-01T10:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Problem: ERROR TcpChannel - Fatal error on accept socket: Software caused connection abort</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Problem-ERROR-TcpChannel-Fatal-error-on-accept-socket/m-p/61919#M12383</link>
      <description>&lt;P&gt;According to Splunk support this Issue wil be fixed in 4.3.1.&lt;BR /&gt;
Apparently the root cause of the problem is, that busy indexers can't send TCP Acks fast enough.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2012 07:32:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Problem-ERROR-TcpChannel-Fatal-error-on-accept-socket/m-p/61919#M12383</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2012-02-02T07:32:00Z</dc:date>
    </item>
  </channel>
</rss>

