The Splunk Stream forwarders on my two primary DNS servers are failing every couple of hours for a TCP reassembly queue overflow. I tried doubling the queue size and filtering out all internal DNS traffic, but the agents still shutdown daily. Has anyone dealt with this before and know what settings to tweak?