<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic typo on inputs.conf for splunktcp-ssl compressed option in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/typo-on-inputs-conf-for-splunktcp-ssl-compressed-option/m-p/121534#M25207</link>
    <description>&lt;P&gt;Since I upgraded to 6.0, I see this warning &lt;BR /&gt;
Possible typo in stanza [splunktcp-ssl:9997] in /splunk/etc/system/local/inputs.conf, line 5: compressed = true &lt;BR /&gt;
Did you mean 'concurrentChannelLimit'? &lt;BR /&gt;
Did you mean 'connection_host'? &lt;/P&gt;</description>
    <pubDate>Wed, 30 Oct 2013 00:26:55 GMT</pubDate>
    <dc:creator>mataharry</dc:creator>
    <dc:date>2013-10-30T00:26:55Z</dc:date>
    <item>
      <title>typo on inputs.conf for splunktcp-ssl compressed option</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/typo-on-inputs-conf-for-splunktcp-ssl-compressed-option/m-p/121534#M25207</link>
      <description>&lt;P&gt;Since I upgraded to 6.0, I see this warning &lt;BR /&gt;
Possible typo in stanza [splunktcp-ssl:9997] in /splunk/etc/system/local/inputs.conf, line 5: compressed = true &lt;BR /&gt;
Did you mean 'concurrentChannelLimit'? &lt;BR /&gt;
Did you mean 'connection_host'? &lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2013 00:26:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/typo-on-inputs-conf-for-splunktcp-ssl-compressed-option/m-p/121534#M25207</guid>
      <dc:creator>mataharry</dc:creator>
      <dc:date>2013-10-30T00:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: typo on inputs.conf for splunktcp-ssl compressed option</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/typo-on-inputs-conf-for-splunktcp-ssl-compressed-option/m-p/121535#M25208</link>
      <description>&lt;P&gt;In latest splunk 5.* and 6.&lt;EM&gt;, the option **compressed&lt;/EM&gt;* has been removed from the inputs for &lt;STRONG&gt;splunktcp-ssl&lt;/STRONG&gt; stanza. &lt;/P&gt;

&lt;P&gt;[EDIT]&lt;BR /&gt;
this is causing typo warnings. Beware, the indexer &lt;STRONG&gt;does not honor&lt;/STRONG&gt; the forwarder configuration. If you have compression setup on the old forwarders, you need to have the same  at the indexer level.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:08:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/typo-on-inputs-conf-for-splunktcp-ssl-compressed-option/m-p/121535#M25208</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2020-09-28T15:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: typo on inputs.conf for splunktcp-ssl compressed option</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/typo-on-inputs-conf-for-splunktcp-ssl-compressed-option/m-p/121536#M25209</link>
      <description>&lt;P&gt;After upgrading to Splunk 5.0.4 or later, the "Possible typo in stanza ... compressed = true" on stdout will be displayed if Splunk was configured to use a combination of SSL compression and the non-SSL compression.&lt;BR /&gt;
Until you plan to change the non-SSL compression setting on all of the forwarders, &lt;STRONG&gt;do not&lt;/STRONG&gt; remove this setting from the inputs.conf after upgrading; changing it will block all forwarder communications that attempt to use non-SSL compression.&lt;/P&gt;

&lt;P&gt;The typo warning is about a deprecated setting for SSL communications only. The warning does not stop the port from accepting inbound communications from a forwarder using both compression options. The forwarders will continue to function normally.&lt;BR /&gt;
The compression setting is required to be synchronized between the outputs.conf on the forwarders and the inputs.conf on the indexers. Splunk does not dynamically adapt to compression settings.&lt;/P&gt;

&lt;P&gt;Prior to Splunk 4.3, the setting for Splunk-to-Splunk communications using the setting 'compressed = true' was applicable to both SSL and non-SSL forwarder communications.&lt;BR /&gt;
The behavior for the setting changed after version 4.3.1 so that *compressed = tru*e applies to non-SSL forwarder communications only.&lt;BR /&gt;
SSL compression is managed by the setting useClientSSLCompression in server.conf and is enabled by default.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/typo-on-inputs-conf-for-splunktcp-ssl-compressed-option/m-p/121536#M25209</guid>
      <dc:creator>ekost</dc:creator>
      <dc:date>2020-09-28T15:17:02Z</dc:date>
    </item>
  </channel>
</rss>

