<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to resolve &amp;quot;TcpOutputProc - Queue for group ICSRouting-checkpoint has begun dropping events&amp;quot; error? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291746#M55583</link>
    <description>&lt;P&gt;So till now my research indicates that it may be related to the tcp session timeout on the firewall in between my HF and the remote syslog. to be continued...&lt;/P&gt;</description>
    <pubDate>Mon, 03 Apr 2017 16:38:50 GMT</pubDate>
    <dc:creator>sassens1</dc:creator>
    <dc:date>2017-04-03T16:38:50Z</dc:date>
    <item>
      <title>How to resolve "TcpOutputProc - Queue for group ICSRouting-checkpoint has begun dropping events" error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291744#M55581</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We use a Heavy Forwarder (HF) to forward CheckPoint logs to an external third-party SIEM using the TCP protocol.&lt;BR /&gt;
I have noticed from time to time this kind of errors:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;01-25-2017 15:47:44.071 +0100 INFO TcpOutputProc - Queue for group ICSRouting-checkpoint has stopped dropping events
01-25-2017 15:47:44.688 +0100 WARN TcpOutputProc - Queue for group ICSRouting-checkpoint has begun dropping events
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;just a few milliseconds of failure?&lt;BR /&gt;
I checked my queue size which seems ok:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;02-08-2017 20:57:22.077 +0100 INFO Metrics - group=queue, ingest_pipe=0, name=tcpout_icsrouting-checkpoint, max_size=512000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However I'm not sure my parsing queue is big enough if I rely on the largest_size &amp;gt; max_size_kb:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;02-08-2017 20:59:26.082 +0100 INFO Metrics - group=queue, ingest_pipe=1, name=parsingqueue, max_size_kb=6144, current_size_kb=0, current_size=0, largest_size=7494, smallest_size=0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I don't have any alert from the Distributed Management Console (DMC), CPU/MEM are fine, anything else I should look at?&lt;BR /&gt;
Could it be the third party syslog that is not handling all the traffic and cannot ack every packet my HF transmits?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:48:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291744#M55581</guid>
      <dc:creator>sassens1</dc:creator>
      <dc:date>2020-09-29T12:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "TcpOutputProc - Queue for group ICSRouting-checkpoint has begun dropping events" error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291745#M55582</link>
      <description>&lt;P&gt;no one? &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 10:53:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291745#M55582</guid>
      <dc:creator>sassens1</dc:creator>
      <dc:date>2017-03-14T10:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "TcpOutputProc - Queue for group ICSRouting-checkpoint has begun dropping events" error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291746#M55583</link>
      <description>&lt;P&gt;So till now my research indicates that it may be related to the tcp session timeout on the firewall in between my HF and the remote syslog. to be continued...&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 16:38:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291746#M55583</guid>
      <dc:creator>sassens1</dc:creator>
      <dc:date>2017-04-03T16:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "TcpOutputProc - Queue for group ICSRouting-checkpoint has begun dropping events" error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291747#M55584</link>
      <description>&lt;P&gt;did this end up being the cause of your issues?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 20:46:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291747#M55584</guid>
      <dc:creator>dflodstrom</dc:creator>
      <dc:date>2017-08-22T20:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "TcpOutputProc - Queue for group ICSRouting-checkpoint has begun dropping events" error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291748#M55585</link>
      <description>&lt;P&gt;@sassens1 Did you find out the root cause that caused this issue?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 18:16:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291748#M55585</guid>
      <dc:creator>vsingla1</dc:creator>
      <dc:date>2018-12-13T18:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "TcpOutputProc - Queue for group ICSRouting-checkpoint has begun dropping events" error?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291749#M55586</link>
      <description>&lt;P&gt;Is this issue still outstanding? We are having the same issue. Any possible solution? thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 12:02:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-TcpOutputProc-Queue-for-group-ICSRouting/m-p/291749#M55586</guid>
      <dc:creator>marlongarcia</dc:creator>
      <dc:date>2019-08-07T12:02:05Z</dc:date>
    </item>
  </channel>
</rss>

