All Apps and Add-ons

Stream App - TCP reassembly queue size

sttkyo
New Member

Hello,

I'm using Splunk App 7.1.0 to capture HTTP traffic and I got several warning messages like below :

2017-04-11 13:07:11 WARN 140491406145280 stream.SnifferReactor - TCP reassembly queue overflow [c=1.212.130.83:40756, s=211.188.236.191:8080]

1) Is there any parameter to increase TCP reassembly queue size? I already increase the maxTcpReassemblyPacketCount to 1000000 but it's not helpful.

2) Does any packet loss possible when this warning happend?

Thanks in advance

Tags (1)
0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

Hello @sttkyo,

TCP reassembly queue overflow usually occurs when there's some issue with reassembling TCP packet flow for the deep packet inspection layer. One of the most common cases is when only one side of the conversation is captured. Currently there's no parameter to increase the TCP reassembly queue size. This warning doesn't cause packet loss per se, but it may cause degradation of the quality of Stream generated data.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...