<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why some of our indexers stop listening on port 9997? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-some-of-our-indexers-stop-listening-on-port-9997/m-p/251453#M48398</link>
    <description>&lt;P&gt;Yesterday we realized that three of our six production indexers stop listening on port 9997. We bounced them and all went back to normal. This morning, one of them stop listening on port 9997. Just bounced it and it's fine for now.&lt;/P&gt;

&lt;P&gt;What can it be?&lt;/P&gt;

&lt;P&gt;After bouncing -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$ netstat  -plnt | grep 9997
(Not all processes could be identified, non-owned process info
 will not be shown, you would have to be root to see it all.)
tcp        0      0 0.0.0.0:9997            0.0.0.0:*               LISTEN      10108/splunkd
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 24 Jan 2017 14:20:26 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2017-01-24T14:20:26Z</dc:date>
    <item>
      <title>Why some of our indexers stop listening on port 9997?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-some-of-our-indexers-stop-listening-on-port-9997/m-p/251453#M48398</link>
      <description>&lt;P&gt;Yesterday we realized that three of our six production indexers stop listening on port 9997. We bounced them and all went back to normal. This morning, one of them stop listening on port 9997. Just bounced it and it's fine for now.&lt;/P&gt;

&lt;P&gt;What can it be?&lt;/P&gt;

&lt;P&gt;After bouncing -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$ netstat  -plnt | grep 9997
(Not all processes could be identified, non-owned process info
 will not be shown, you would have to be root to see it all.)
tcp        0      0 0.0.0.0:9997            0.0.0.0:*               LISTEN      10108/splunkd
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 24 Jan 2017 14:20:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-some-of-our-indexers-stop-listening-on-port-9997/m-p/251453#M48398</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-01-24T14:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why some of our indexers stop listening on port 9997?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-some-of-our-indexers-stop-listening-on-port-9997/m-p/251454#M48399</link>
      <description>&lt;P&gt;when your queues are blocked and the blocking reaches back to input queue the indexer will stop listening to give it time to catch up.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/Forwarding/Receiverconnection#Closed_receiver_socket" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.1/Forwarding/Receiverconnection#Closed_receiver_socket&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:35:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-some-of-our-indexers-stop-listening-on-port-9997/m-p/251454#M48399</guid>
      <dc:creator>phoffman_splunk</dc:creator>
      <dc:date>2020-09-29T12:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why some of our indexers stop listening on port 9997?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-some-of-our-indexers-stop-listening-on-port-9997/m-p/251455#M48400</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Closed receiver socket"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2362iCBA02DB0165B4612/image-size/large?v=v2&amp;amp;px=999" role="button" title="Closed receiver socket" alt="Closed receiver socket" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;When I run the following - &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal host=x1209 group=queue blocked name=indexqueue | timechart count by queue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I don't see the results matching the -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal host=x1209 group=queue unblocked name=indexqueue | timechart count by queue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Meaning, &lt;STRONG&gt;blocked&lt;/STRONG&gt; versus &lt;STRONG&gt;unblocked&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;My problem is that only by bouncing Splunk, the 9997 port becomes open and it starts indexing. According to the &lt;CODE&gt;License Usage - Previous 30 Days&lt;/CODE&gt;, this indexer hasn't indexed any data for three days until the bounce.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 19:24:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-some-of-our-indexers-stop-listening-on-port-9997/m-p/251455#M48400</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-01-24T19:24:09Z</dc:date>
    </item>
  </channel>
</rss>

