<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexer stops receiving data from forwarders in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-stops-receiving-data-from-forwarders/m-p/252638#M99189</link>
    <description>&lt;P&gt;nice work!&lt;/P&gt;</description>
    <pubDate>Fri, 18 Mar 2016 19:13:18 GMT</pubDate>
    <dc:creator>muebel</dc:creator>
    <dc:date>2016-03-18T19:13:18Z</dc:date>
    <item>
      <title>Indexer stops receiving data from forwarders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-stops-receiving-data-from-forwarders/m-p/252637#M99188</link>
      <description>&lt;P&gt;This is less of a question and more of a record on Splunk Answers of an issue we ran into.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Symptoms:&lt;/STRONG&gt;&lt;BR /&gt;
You are on Red Hat 6.6, 7.0, or 7.1&lt;/P&gt;

&lt;P&gt;The Indexer stops receiving data from Forwarders, but looks to be up and running fine otherwise.  In a sense it seems stuck for our TCP input port on &lt;EM&gt;splunkd&lt;/EM&gt;.  For example, the Indexer still participates as a peer for any searches, and the Indexer also looks to continue indexing any data generated locally - internal Splunk logs or scripted inputs running on that Indexer.  Essentially the TCP input port is bad, but the &lt;EM&gt;splunkd&lt;/EM&gt; admin port is fine.&lt;/P&gt;

&lt;P&gt;When running the following search, any Indexers having this problem would show up has having 1 or 0 Distinct Hosts since they weren't able to receive anything from Forwarders:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=splunkd earliest=-15m | stats count as event_count, dc(host) as distinct_hosts by splunk_server
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also, we would notice a lot of TCP connections sitting in a CLOSE_WAIT or SYN_RECV state when running &lt;EM&gt;netstat -an&lt;/EM&gt; on the Indexer.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Use &lt;EM&gt;pstack&lt;/EM&gt; to dump a list of processes associated with &lt;EM&gt;splunkd&lt;/EM&gt;.  This will magically fix things without having to restart the Indexer:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;pstack `head -1 $SPLUNK_HOME/var/run/splunk/splunkd.pid`
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Solution:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;There is a bug in Red Hat that causes things to go awry:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://access.redhat.com/solutions/1386323" target="_blank"&gt;https://access.redhat.com/solutions/1386323&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In our case, the solution was to patch from kernel  &lt;STRONG&gt;2.6.32-504.8.1&lt;/STRONG&gt; to &lt;STRONG&gt;2.6.32-504.16.2&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Environment Details:&lt;/STRONG&gt;&lt;BR /&gt;
 - &lt;STRONG&gt;Splunk&lt;/STRONG&gt;: 6.2.5 (build 272645)&lt;BR /&gt;
 - &lt;STRONG&gt;OS&lt;/STRONG&gt;: Red Hat Linux 2.6.32-504.8.1.el6.x86_64 #1 SMP Fri Dec 19 12:09:25 EST 2014 x86_64 x86_64 x86_64 GNU/Linux&lt;BR /&gt;
 - &lt;STRONG&gt;HW&lt;/STRONG&gt;: Cisco UCS C240&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:08:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-stops-receiving-data-from-forwarders/m-p/252637#M99188</guid>
      <dc:creator>jhupka</dc:creator>
      <dc:date>2020-09-29T09:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer stops receiving data from forwarders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-stops-receiving-data-from-forwarders/m-p/252638#M99189</link>
      <description>&lt;P&gt;nice work!&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 19:13:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-stops-receiving-data-from-forwarders/m-p/252638#M99189</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2016-03-18T19:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer stops receiving data from forwarders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-stops-receiving-data-from-forwarders/m-p/252639#M99190</link>
      <description>&lt;P&gt;Solution:&lt;/P&gt;

&lt;P&gt;There is a bug in Red Hat that causes things to go awry:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://access.redhat.com/solutions/1386323"&gt;https://access.redhat.com/solutions/1386323&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In our case, the solution was to patch from kernel 2.6.32-504.8.1 to 2.6.32-504.16.2&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 19:35:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-stops-receiving-data-from-forwarders/m-p/252639#M99190</guid>
      <dc:creator>jhupka</dc:creator>
      <dc:date>2016-03-18T19:35:07Z</dc:date>
    </item>
  </channel>
</rss>

