<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ERROR TcpInputProc - Message rejected. Received unexpected 1009858864 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204191#M40297</link>
    <description>&lt;P&gt;yes clearly a misunderstanding (in my case) of how heavy (intermediate) forwarders should deal with their input data&lt;/P&gt;</description>
    <pubDate>Thu, 04 Aug 2016 05:16:28 GMT</pubDate>
    <dc:creator>lauMarot</dc:creator>
    <dc:date>2016-08-04T05:16:28Z</dc:date>
    <item>
      <title>ERROR TcpInputProc - Message rejected. Received unexpected 1009858864</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204188#M40294</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;problem on splunk enterprise 6.4.2&lt;/P&gt;

&lt;P&gt;I've just set up an intermediate (heavy) splunk 6.4 forwarder between my syslog-ng server and my indexer. This heavy forwarder is supposed to help me filtering F5 BigIP logs&lt;/P&gt;

&lt;P&gt;1 - Receiving was set up on Indexer to listen on port 5141 (not 9997 default port) usin web Gui (then i double check that the stanza is ok in inputs.conf)&lt;/P&gt;

&lt;P&gt;2 - Forwarding was activated from forwarder using web Gui (menu "Forwarding ans Receiving / Forward data")  adding "xxx.xxx.xxx.xxx:5141" where xxx.xxx.xxx.xxx is the IP of my indexer&lt;/P&gt;

&lt;P&gt;3 - log Stream can be displayed on idexer using tcpdump&lt;/P&gt;

&lt;P&gt;4 - no data is  collected in any index and the error " ERROR TcpInputProc - Message rejected. Received unexpected 1009858864" is thrown&lt;/P&gt;

&lt;P&gt;What could be wrong ?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 12:47:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204188#M40294</guid>
      <dc:creator>lauMarot</dc:creator>
      <dc:date>2016-08-03T12:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpInputProc - Message rejected. Received unexpected 1009858864</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204189#M40295</link>
      <description>&lt;P&gt;just one dumb thing I forgot to mention : I used to think It was possible to grab the Syslog stream of my device in my Forwarder directly through TCP receiver of my Forwarder (see the screenshot)&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1673iF858273AB340FAD5/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 20:00:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204189#M40295</guid>
      <dc:creator>lauMarot</dc:creator>
      <dc:date>2016-08-03T20:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpInputProc - Message rejected. Received unexpected 1009858864</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204190#M40296</link>
      <description>&lt;P&gt;A similar case at &lt;A href="https://answers.splunk.com/answers/194810/62-forwarder-configuration-on-linux-why-am-i-getti.html"&gt;6.2 Forwarder Configuration on Linux: Why am I getting error "TcpInputProc - Message rejected. Received unexpected 369295616 byte message!" in server's splunkd.log?&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;It ended up being a misconfiguration - &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1674i4DD8B7466A9DEEC3/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 20:27:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204190#M40296</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-08-03T20:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpInputProc - Message rejected. Received unexpected 1009858864</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204191#M40297</link>
      <description>&lt;P&gt;yes clearly a misunderstanding (in my case) of how heavy (intermediate) forwarders should deal with their input data&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 05:16:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204191#M40297</guid>
      <dc:creator>lauMarot</dc:creator>
      <dc:date>2016-08-04T05:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpInputProc - Message rejected. Received unexpected 1009858864</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204192#M40298</link>
      <description>&lt;P&gt;Hi Laurent,&lt;/P&gt;

&lt;P&gt;The fwd (whatever version) can receive syslog streams, as any other fwd.&lt;BR /&gt;
keep in mind that if you do not need any functions from the Heavy fwd (web interface, advanced filtering), you should use the Universal fwd (even to act as a relay). &lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 07:27:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204192#M40298</guid>
      <dc:creator>mdessus_splunk</dc:creator>
      <dc:date>2016-08-05T07:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpInputProc - Message rejected. Received unexpected 1009858864</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204193#M40299</link>
      <description>&lt;P&gt;yeap ! Understood ! But receiving must be set from "Data inputs » UDP " and  not "Forwarding and receiving » Receive data » Add new " (my mistake) &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 07:42:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Message-rejected-Received-unexpected/m-p/204193#M40299</guid>
      <dc:creator>lauMarot</dc:creator>
      <dc:date>2016-08-05T07:42:07Z</dc:date>
    </item>
  </channel>
</rss>

