<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarders blocking / Splunk Cloud  Dead Letter Queue (DLQ), due to a Persistent Queue (PQ) problem with S2S protoco in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/744795#M10399</link>
    <description>&lt;P&gt;9.3.3 is fine.&lt;BR /&gt;&lt;SPAN&gt;9.4.x/9.3.2/9.2.4/9.1.7 and above has the fix.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Apr 2025 15:18:06 GMT</pubDate>
    <dc:creator>hrawat</dc:creator>
    <dc:date>2025-04-23T15:18:06Z</dc:date>
    <item>
      <title>Forwarders blocking / Splunk Cloud  Dead Letter Queue (DLQ), due to a Persistent Queue (PQ) problem with S2S protocol.</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/703859#M10331</link>
      <description>&lt;P&gt;&lt;SPAN&gt;See&amp;nbsp;SPL-248479 in &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.0/ReleaseNotes/Fixedissues#Universal_forwarder_issues" target="_blank" rel="noopener"&gt;release notes&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;If you are using persistent queue and see following errors in splunkd.log.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ERROR TcpInputProc - Encountered Streaming S2S error

1. "Cannot register new_channel"

2. "Invalid payload_size"

3. "Too many bytes_used"

4. "Message rejected. Received unexpected message of size"

5. "not a valid combined field name/value type for data received"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Other S2S streaming errors as well.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;You should upgrade your&amp;nbsp;HF/IHF/IUF/IDX instance (if using persistent queue ) to following patches.&lt;BR /&gt;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;9.4.0/9.3.2/9.2.4/9.1.7 and above.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;This patch also fixes all the known PQ related crashes and other PQ issues.&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2025 14:26:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/703859#M10331</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2025-05-05T14:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarders blocking / Splunk Cloud  Dead Letter Queue (DLQ), due to a Persistent Queue (PQ) problem with S2S protoco</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/744722#M10397</link>
      <description>&lt;P&gt;Hey,&lt;BR /&gt;Email was release today from&amp;nbsp;Splunk Cloud Platform Team stating&amp;nbsp; to fix this issue we should patch up to&amp;nbsp;9.4.0, 9.3.2, 9.2.4 or 9.1.7 as you have mentioned above.&lt;BR /&gt;Last month in the "Splunk Security Advisories" it said to patch up to&amp;nbsp;&lt;SPAN&gt;9.4.1, 9.3.3, 9.2.5, and 9.1.8 so if we are on the&amp;nbsp;9.4.1, 9.3.3, 9.2.5, and 9.1.8 versions, we are in the fix?&lt;BR /&gt;Second question,&amp;nbsp; If Splunk issued the recommendation to patch up to a higher level patch, why would they come back and recommend patch to a lower version with security vulnerabilities instead of patching up?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 21:19:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/744722#M10397</guid>
      <dc:creator>edhealea</dc:creator>
      <dc:date>2025-04-22T21:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarders blocking / Splunk Cloud  Dead Letter Queue (DLQ), due to a Persistent Queue (PQ) problem with S2S protoco</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/744788#M10398</link>
      <description>&lt;P&gt;What should be plan for customers who recently upgraded to 9.3.3?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 13:56:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/744788#M10398</guid>
      <dc:creator>inderjot</dc:creator>
      <dc:date>2025-04-23T13:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarders blocking / Splunk Cloud  Dead Letter Queue (DLQ), due to a Persistent Queue (PQ) problem with S2S protoco</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/744795#M10399</link>
      <description>&lt;P&gt;9.3.3 is fine.&lt;BR /&gt;&lt;SPAN&gt;9.4.x/9.3.2/9.2.4/9.1.7 and above has the fix.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 15:18:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/744795#M10399</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2025-04-23T15:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarders blocking / Splunk Cloud  Dead Letter Queue (DLQ), due to a Persistent Queue (PQ) problem with S2S protoco</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/744797#M10400</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;gt;9.4.1, 9.3.3, 9.2.5, and 9.1.8 so if we are on the&amp;nbsp;9.4.1, 9.3.3, 9.2.5, and 9.1.8 versions, we are in the fix?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Yes.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;SPAN&gt;Last month in the "Splunk Security Advisories" it said to patch up to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;9.4.1, 9.3.3, 9.2.5, and 9.1.8 so if we are on the&amp;nbsp;9.4.1, 9.3.3, 9.2.5, and 9.1.8 versions, we are in the fix?&lt;BR /&gt;&lt;/SPAN&gt;I think the new advisory is just telling the fix is in&amp;nbsp;&lt;SPAN&gt;9.4.0, 9.3.2, 9.2.4 or 9.1.7 and above&amp;nbsp;. However if you are already on&amp;nbsp;9.4.1, 9.3.3, 9.2.5, and 9.1.8 versions and above, you can ignore new email.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 15:23:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/744797#M10400</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2025-04-23T15:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarders blocking / Splunk Cloud  Dead Letter Queue (DLQ), due to a Persistent Queue (PQ) problem with S2S protoco</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/744799#M10401</link>
      <description>&lt;P&gt;Thanks for confirming&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 15:27:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/744799#M10401</guid>
      <dc:creator>inderjot</dc:creator>
      <dc:date>2025-04-23T15:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarders blocking / Splunk Cloud  Dead Letter Queue (DLQ), due to a Persistent Queue (PQ) problem with S2S protoco</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/745069#M10402</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/118813"&gt;@hrawat&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;The email sent titled "Splunk Service Bulletin Notification" was very poorly written. It explicitly states to upgrade to one of the following versions, it doesn't say "or later".&lt;/P&gt;&lt;P&gt;We have recently upgraded all our forwarders to be running 9.4.1, which according to the service bulletin email isn't fixed, only 9.4.0 is (was there regression, or is the email wrong?).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AF_Ops_0-1745792447509.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38765i384009A16043DF92/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AF_Ops_0-1745792447509.png" alt="AF_Ops_0-1745792447509.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Apr 2025 22:23:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/745069#M10402</guid>
      <dc:creator>AF_Ops</dc:creator>
      <dc:date>2025-04-27T22:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarders blocking / Splunk Cloud  Dead Letter Queue (DLQ), due to a Persistent Queue (PQ) problem with S2S protoco</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/745092#M10403</link>
      <description>&lt;P&gt;&lt;SPAN&gt;9.4.0/9.3.2/9.2.4/9.1.7 and above has the fix. Since you are already on 9.4.1, it also has the fix.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 10:49:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/745092#M10403</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2025-04-28T10:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarders blocking / Splunk Cloud  Dead Letter Queue (DLQ), due to a Persistent Queue (PQ) problem with S2S protoco</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/745492#M10416</link>
      <description>&lt;H4&gt;&lt;STRONG&gt;For customers hitting&amp;nbsp;&lt;FONT color="#993300"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Cannot&lt;/SPAN&gt; &lt;SPAN class=""&gt;register&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;new_channel&amp;nbsp;&lt;FONT color="#000000"&gt;error regardless of persistent queue at IF,&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;STRONG&gt;applying &lt;/STRONG&gt;&lt;STRONG&gt;&lt;FONT color="#008000"&gt;9.4.x/9.3.2/9.2.4/9.1.7 and above&lt;/FONT&gt; should fix the issue or reduce the chance of events entering&amp;nbsp; into splunkcloud DLQ.&lt;/STRONG&gt;&lt;/H4&gt;</description>
      <pubDate>Mon, 05 May 2025 14:24:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Forwarders-blocking-Splunk-Cloud-Dead-Letter-Queue-DLQ-due-to-a/m-p/745492#M10416</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2025-05-05T14:24:23Z</dc:date>
    </item>
  </channel>
</rss>

