<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk closing TCP port 9997 (forwarder port) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96286#M20075</link>
    <description>&lt;P&gt;It's a shot in the dark without more information, but I had this issue before.  Are you using the deployment server in your environment?  Is it possible your forwarders' outputs.conf got deployed to your indexer?&lt;/P&gt;

&lt;P&gt;On the indexer:&lt;BR /&gt;
./splunk cmd btool outputs list --debug&lt;/P&gt;

&lt;P&gt;See if you're somehow looping your inputs back to itself.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jul 2012 17:40:17 GMT</pubDate>
    <dc:creator>mikelanghorst</dc:creator>
    <dc:date>2012-07-12T17:40:17Z</dc:date>
    <item>
      <title>Splunk closing TCP port 9997 (forwarder port)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96282#M20071</link>
      <description>&lt;P&gt;I upgraded to 4.3.3 on an indexer that never had any problems before this point in time and now the indexer is dropping all forwarded events on the floor with messages like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;07-11-2012 12:44:17.568 -0500 INFO TcpInputProc - Stopping IPv4 port 9997
07-11-2012 12:44:17.568 -0500 WARN TcpInputProc - Stopping all listening ports. Queues blocked for more than 300 seconds
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I've seen similar questions appear like this on splunkanswers, but the suggested resolutions (involving fishbucket) dont seem to apply to my case?&lt;/P&gt;

&lt;P&gt;I turned on splunk debugging, but it doesn't lead me to any better conclusions.&lt;/P&gt;

&lt;P&gt;What queues is it referring to? The box is ripe with CPU, disk, and RAM. It cant possibly be overloaded; it's not &lt;EM&gt;doing&lt;/EM&gt; anything.&lt;/P&gt;

&lt;P&gt;Support is being a lame duck; taking their time staring at walls. In the meantime my primary splunk indexer is not indexing anything because it's not receiving anything from the forwarders.&lt;/P&gt;

&lt;P&gt;Does anyone have any clues as to where I could look? If it's not resolved by tomorrow I'm re-installing splunk on the primary indexer as this is not something that can wait.&lt;/P&gt;

&lt;P&gt;Thanks in advance for any help and guidance you can provide.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2012 02:14:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96282#M20071</guid>
      <dc:creator>caphrim007</dc:creator>
      <dc:date>2012-07-12T02:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk closing TCP port 9997 (forwarder port)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96283#M20072</link>
      <description>&lt;P&gt;The queues that are mentioned by that message are those that lead into the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Datapipeline"&gt;data pipelines&lt;/A&gt; where splunkd shapes your data into events before indexing those on disk.&lt;/P&gt;

&lt;P&gt;This message would indicate that there is a bottleneck in one of those pipelines, which causes the queue that feeds it and all queues upstream to fill up, all the way to the queue that accepts incoming events from forwarders (splunktcpin).&lt;/P&gt;

&lt;P&gt;This is obviously undesirable, but keep in mind that your forwarder events are &lt;EM&gt;not&lt;/EM&gt; being dropped. Instead, the forwarders will pause their data inputs and resume once the indexer is able to process data again.&lt;/P&gt;

&lt;P&gt;When seeing such a message, the first thing that you should do is to determine the fill percentage of the queues leading to the 4 main data pipelines : parsing -&amp;gt; merging -&amp;gt; typing -&amp;gt; indexing.&lt;/P&gt;

&lt;P&gt;By determining which is the most downstream queue to be saturated, you can get an idea of why there is a bottleneck there.&lt;/P&gt;

&lt;P&gt;A simple way to gain visibility of the state of event-processing queues is to use the "indexing performance" view of the &lt;A href="http://www.splunk.com/goto/sos"&gt;Splunk on Splunk app&lt;/A&gt;. For details on how to install the app, check &lt;A href="http://splunk-base.splunk.com/answers/38091"&gt;this Splunk Answer&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;If you can post a screenshot showing the panels of that view, I can try to help you further.&lt;/P&gt;

&lt;P&gt;Incidentally, what is the case number that you opened with Splunk support? I can check in on it for you.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2012 04:59:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96283#M20072</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2012-07-12T04:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk closing TCP port 9997 (forwarder port)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96284#M20073</link>
      <description>&lt;P&gt;Appears I have it installed, but when going to use it, I get this error.&lt;/P&gt;

&lt;P&gt;Splunk encountered the following unknown module: "sosFTR" .  The view may not load properly&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2012 11:30:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96284#M20073</guid>
      <dc:creator>caphrim007</dc:creator>
      <dc:date>2012-07-12T11:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk closing TCP port 9997 (forwarder port)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96285#M20074</link>
      <description>&lt;P&gt;Sideview Utils. Next time I'll read before asking&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2012 11:37:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96285#M20074</guid>
      <dc:creator>caphrim007</dc:creator>
      <dc:date>2012-07-12T11:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk closing TCP port 9997 (forwarder port)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96286#M20075</link>
      <description>&lt;P&gt;It's a shot in the dark without more information, but I had this issue before.  Are you using the deployment server in your environment?  Is it possible your forwarders' outputs.conf got deployed to your indexer?&lt;/P&gt;

&lt;P&gt;On the indexer:&lt;BR /&gt;
./splunk cmd btool outputs list --debug&lt;/P&gt;

&lt;P&gt;See if you're somehow looping your inputs back to itself.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2012 17:40:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96286#M20075</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-07-12T17:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk closing TCP port 9997 (forwarder port)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96287#M20076</link>
      <description>&lt;P&gt;That would be consistent with the high-level symptom described.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2012 18:03:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96287#M20076</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2012-07-12T18:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk closing TCP port 9997 (forwarder port)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96288#M20077</link>
      <description>&lt;P&gt;I try to avoid staring at walls whenever I can &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2015 22:17:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96288#M20077</guid>
      <dc:creator>KpiBuff</dc:creator>
      <dc:date>2015-02-05T22:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk closing TCP port 9997 (forwarder port)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96289#M20078</link>
      <description>&lt;P&gt;What was the issue?  Please help..  We are facing  same issue..  If this is resolved,  can you please give snippet of inputs. Conf and output. Conf files.. &lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 14:11:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96289#M20078</guid>
      <dc:creator>k_harini</dc:creator>
      <dc:date>2017-05-25T14:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk closing TCP port 9997 (forwarder port)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96290#M20079</link>
      <description>&lt;P&gt;Tat was the issue for me..  Looping back to itself &lt;/P&gt;</description>
      <pubDate>Sat, 27 May 2017 02:11:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-closing-TCP-port-9997-forwarder-port/m-p/96290#M20079</guid>
      <dc:creator>k_harini</dc:creator>
      <dc:date>2017-05-27T02:11:49Z</dc:date>
    </item>
  </channel>
</rss>

