<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Open TCP Connections from forwarders to indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Open-TCP-Connections-from-forwarders-to-indexer/m-p/180412#M36180</link>
    <description>&lt;P&gt;When watching the network traffic from a Splunk Universal Forwarder to a Indexer there appears to be two connections. &lt;/P&gt;

&lt;P&gt;There is a standard “data forwarding connection” (long lived, shows up with sourceIp and sourcePort in metrics.log under the tcpin_connections group) but there also appears to be a secondary connection opened by the forwarder. The second connection occurs every 30 seconds and lasts about 1 second after which it seemed to be closed by the forwarder.&lt;/P&gt;

&lt;P&gt;What is the second connection used for? Does it indicate a problem with Splunk?&lt;/P&gt;</description>
    <pubDate>Wed, 28 May 2014 07:25:11 GMT</pubDate>
    <dc:creator>dshakespeare_sp</dc:creator>
    <dc:date>2014-05-28T07:25:11Z</dc:date>
    <item>
      <title>Open TCP Connections from forwarders to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Open-TCP-Connections-from-forwarders-to-indexer/m-p/180412#M36180</link>
      <description>&lt;P&gt;When watching the network traffic from a Splunk Universal Forwarder to a Indexer there appears to be two connections. &lt;/P&gt;

&lt;P&gt;There is a standard “data forwarding connection” (long lived, shows up with sourceIp and sourcePort in metrics.log under the tcpin_connections group) but there also appears to be a secondary connection opened by the forwarder. The second connection occurs every 30 seconds and lasts about 1 second after which it seemed to be closed by the forwarder.&lt;/P&gt;

&lt;P&gt;What is the second connection used for? Does it indicate a problem with Splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2014 07:25:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Open-TCP-Connections-from-forwarders-to-indexer/m-p/180412#M36180</guid>
      <dc:creator>dshakespeare_sp</dc:creator>
      <dc:date>2014-05-28T07:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: Open TCP Connections from forwarders to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Open-TCP-Connections-from-forwarders-to-indexer/m-p/180413#M36181</link>
      <description>&lt;P&gt;The secondary connection is a "healthcheck" probe.&lt;BR /&gt;
The forwarder uses this connection to evaluate whether the receiver still in a "good working condition".  When a receiver is effectively stalled so it is not processing more data, or&lt;BR /&gt;
when it is in the process of shutting down, the receiver closes the TCP socket.  A forwarder which cannot connect to the indexer's incoming socket will put the indexer into quarantine and not associate any more data streams with that indexer until the health check works again.  This&lt;BR /&gt;
allows Splunk to try to complete outgoing data streams, and ensures that if data need to be resent (eg useACK timeout) it would not pointlessly select this indexer even if we are already&lt;BR /&gt;
connected to it.&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2014 07:33:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Open-TCP-Connections-from-forwarders-to-indexer/m-p/180413#M36181</guid>
      <dc:creator>dshakespeare_sp</dc:creator>
      <dc:date>2014-05-28T07:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Open TCP Connections from forwarders to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Open-TCP-Connections-from-forwarders-to-indexer/m-p/180414#M36182</link>
      <description>&lt;P&gt;also see &lt;A href="http://wiki.splunk.com/Community:Splunk_Socket_Behavior"&gt;http://wiki.splunk.com/Community:Splunk_Socket_Behavior&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2014 07:38:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Open-TCP-Connections-from-forwarders-to-indexer/m-p/180414#M36182</guid>
      <dc:creator>dshakespeare_sp</dc:creator>
      <dc:date>2014-05-28T07:38:58Z</dc:date>
    </item>
  </channel>
</rss>

