I'm using Splunk App 7.1.0 to capture HTTP traffic and I got several warning messages like below :
2017-04-11 13:07:11 WARN 140491406145280 stream.SnifferReactor - TCP reassembly queue overflow [c=22.214.171.124:40756, s=126.96.36.199:8080]
1) Is there any parameter to increase TCP reassembly queue size? I already increase the maxTcpReassemblyPacketCount to 1000000 but it's not helpful.
2) Does any packet loss possible when this warning happend?
Thanks in advance