<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange warning message, issues Splunking Active Directory in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Strange-warning-message-issues-Splunking-Active-Directory/m-p/129472#M7697</link>
    <description>&lt;P&gt;Issue was due to Forwarder being 5.0 and Indexer being 6.0, thanks, should have noticed that one :S&lt;/P&gt;</description>
    <pubDate>Wed, 06 Nov 2013 01:09:18 GMT</pubDate>
    <dc:creator>samlaw</dc:creator>
    <dc:date>2013-11-06T01:09:18Z</dc:date>
    <item>
      <title>Strange warning message, issues Splunking Active Directory</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Strange-warning-message-issues-Splunking-Active-Directory/m-p/129470#M7695</link>
      <description>&lt;P&gt;Having issues receiving data from my AD, &lt;BR /&gt;
Firewall is set to allow 9997 and 8089 TCP/UDP Outbound and Inbound&lt;/P&gt;

&lt;P&gt;I get the below Error and warning in my splunkd.log&lt;/P&gt;

&lt;P&gt;11-06-2013 06:59:02.526 +1300 ERROR TcpOutputFd - Resurrect failure&lt;BR /&gt;
11-06-2013 06:59:02.994 +1300 WARN  TcpOutputProc - Connected to idx=10.21.12.195:9997. Not using ACK.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2013 19:02:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Strange-warning-message-issues-Splunking-Active-Directory/m-p/129470#M7695</guid>
      <dc:creator>samlaw</dc:creator>
      <dc:date>2013-11-05T19:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Strange warning message, issues Splunking Active Directory</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Strange-warning-message-issues-Splunking-Active-Directory/m-p/129471#M7696</link>
      <description>&lt;P&gt;Looks like a network issue, check these things:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;That port 9997 is not being used by another application.&lt;/LI&gt;
&lt;LI&gt;the local firewall settings on the AD are set up properly. e.g. iptables&lt;/LI&gt;
&lt;LI&gt;Splunk versions are compatible between indexer and forwarder&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;I would also do a packet trace on both the splunk server and the AD machine to confirm that there's no packet loss or strange behaviour from the AD. You can compare it to a packet trace on a machine that works properly to see if there's any discrepancies. &lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2013 21:25:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Strange-warning-message-issues-Splunking-Active-Directory/m-p/129471#M7696</guid>
      <dc:creator>yong_ly</dc:creator>
      <dc:date>2013-11-05T21:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: Strange warning message, issues Splunking Active Directory</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Strange-warning-message-issues-Splunking-Active-Directory/m-p/129472#M7697</link>
      <description>&lt;P&gt;Issue was due to Forwarder being 5.0 and Indexer being 6.0, thanks, should have noticed that one :S&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2013 01:09:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Strange-warning-message-issues-Splunking-Active-Directory/m-p/129472#M7697</guid>
      <dc:creator>samlaw</dc:creator>
      <dc:date>2013-11-06T01:09:18Z</dc:date>
    </item>
  </channel>
</rss>

