<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk forwarders  using too many sockets in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarders-using-too-many-sockets/m-p/131946#M97798</link>
    <description>&lt;P&gt;My indexer ports are receiving data. It looks fine. The problem is in the forwarder machine which is exhausting socket availability.  No other ports were initially set&lt;/P&gt;</description>
    <pubDate>Thu, 07 Nov 2013 08:25:26 GMT</pubDate>
    <dc:creator>dtekas</dc:creator>
    <dc:date>2013-11-07T08:25:26Z</dc:date>
    <item>
      <title>splunk forwarders  using too many sockets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarders-using-too-many-sockets/m-p/131944#M97796</link>
      <description>&lt;P&gt;I have the following config in outputs.conf for splunk forwarder installed on a linux machine.&lt;/P&gt;

&lt;P&gt;connectionTimeout = 20&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;BR /&gt;
dropEventsOnQueueFull = -1&lt;BR /&gt;
indexAndForward = false&lt;BR /&gt;
maxConnectionsPerIndexer = 2&lt;BR /&gt;
maxFailuresPerInterval = 2&lt;BR /&gt;
maxQueueSize = 500KB&lt;BR /&gt;
readTimeout = 300&lt;BR /&gt;
secsInFailureInterval = 1&lt;BR /&gt;
useACK = false&lt;BR /&gt;
writeTimeout = 300&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
autoLB = true&lt;BR /&gt;
autoLBFrequency = 30&lt;BR /&gt;
compressed = false&lt;/P&gt;

&lt;P&gt;The forwarder is sending some historical logs too of past few months. As soon as splunk is started lot of processes on that machine cannot process due to lack of open ports as forwarder is using a lot of sockets i guess.&lt;BR /&gt;
Is there anyway to limit the number of sockets it use? &lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2013 06:39:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarders-using-too-many-sockets/m-p/131944#M97796</guid>
      <dc:creator>dtekas</dc:creator>
      <dc:date>2013-11-07T06:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: splunk forwarders  using too many sockets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarders-using-too-many-sockets/m-p/131945#M97797</link>
      <description>&lt;P&gt;Check for any unused ports where initially data was configured to be received but later on stopped for some reason&lt;BR /&gt;
you may remove those unused port using "splunk remove udp (or tcp) port#&amp;gt;&lt;/P&gt;

&lt;P&gt;bit of housekeeping stuff might just help&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2013 07:33:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarders-using-too-many-sockets/m-p/131945#M97797</guid>
      <dc:creator>rawatvineet</dc:creator>
      <dc:date>2013-11-07T07:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: splunk forwarders  using too many sockets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarders-using-too-many-sockets/m-p/131946#M97798</link>
      <description>&lt;P&gt;My indexer ports are receiving data. It looks fine. The problem is in the forwarder machine which is exhausting socket availability.  No other ports were initially set&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2013 08:25:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-forwarders-using-too-many-sockets/m-p/131946#M97798</guid>
      <dc:creator>dtekas</dc:creator>
      <dc:date>2013-11-07T08:25:26Z</dc:date>
    </item>
  </channel>
</rss>

