Deployment Architecture

Indexer shows multiple CLOSE_WAIT sessions on 9997 with forwarders.

sgrey007
New Member

This is probably a follow up to the question asked 20 Mar '12, 02:49 by nebel.
ERROR TcpInputProc - Error encountered for connection
In the process of adding a number of new forwarders to our recently upgraded 5.0.2 (forwarders are still at 4.3.4) we noticed the same messages in splunkd.log on two of 5 indexers.
Further we see in netstat -a, numerous CLOSE_WAIT sessions with many forwarders new and old, forwarders, in some case multiple sessions to a forwarder.
The questions are, what causes it, and are there Splunk recommended TCP tweaks for Linux (CentOS/Redhat/Ubuntu) to resolve this system problem?

0 Karma

ekost
Splunk Employee
Splunk Employee

The symptoms you're describing are similar to a recent post here.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...