<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Indexer Error in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Indexer-Error/m-p/528085#M4639</link>
    <description>&lt;P&gt;We received the below error in splunkd.log on our indexer server. We are using cluster env with 6 indexers. The indexers are coming up and down&lt;/P&gt;&lt;DIV&gt;11-05-2020 07:23:03.304 +0000 ERROR TcpInputProc - Error encountered for connection from src=X.X.X.X:60116. Broken pipe&lt;/DIV&gt;</description>
    <pubDate>Thu, 05 Nov 2020 09:54:41 GMT</pubDate>
    <dc:creator>abhijitnath89ax</dc:creator>
    <dc:date>2020-11-05T09:54:41Z</dc:date>
    <item>
      <title>Splunk Indexer Error</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Indexer-Error/m-p/528085#M4639</link>
      <description>&lt;P&gt;We received the below error in splunkd.log on our indexer server. We are using cluster env with 6 indexers. The indexers are coming up and down&lt;/P&gt;&lt;DIV&gt;11-05-2020 07:23:03.304 +0000 ERROR TcpInputProc - Error encountered for connection from src=X.X.X.X:60116. Broken pipe&lt;/DIV&gt;</description>
      <pubDate>Thu, 05 Nov 2020 09:54:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Indexer-Error/m-p/528085#M4639</guid>
      <dc:creator>abhijitnath89ax</dc:creator>
      <dc:date>2020-11-05T09:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexer Error</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Indexer-Error/m-p/528925#M4647</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/58649"&gt;@abhijitnath89ax&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;After doing some researching about the error you have depicted could be related to the indexers trying to see if the others indexers/receivers are "alive" named a heartbeat function.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Archive/Bronken-pipe-on-splunkd-log-HF-timeouts-on-splunkd-log-on-UF-no/m-p/185535" target="_self"&gt;View solution in original post&lt;/A&gt; by &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/183095"&gt;@hliakathali_spl&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would there happen to be a firewall change either in the network and/or a firewall change on the Splunk Indexers themselves that are prohibiting the connection between them?&lt;/P&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;We hope to hear back from you!&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;V/R,&lt;/DIV&gt;&lt;DIV&gt;nwuest&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 11 Nov 2020 07:19:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Indexer-Error/m-p/528925#M4647</guid>
      <dc:creator>nwuest</dc:creator>
      <dc:date>2020-11-11T07:19:41Z</dc:date>
    </item>
  </channel>
</rss>

