Deployment Architecture

ERROR TcpChannel - Error trying to begin socket accept: An invalid argument was supplied.

alane
Engager

Upgraded Deployment Server / License Server to Version 6. Runs OK for 15 minutes then maxes out CPU and starts to fail with
ERROR TcpChannel - Error trying to begin socket accept: An invalid argument was supplied.
showing in SplunkD log.

Voltaire
Communicator

Are you using IPV6?
I had a similar issue with Splunk 6.0 build 182037. "ERROR TcpChannel - Error trying to begin socket accept: An invalid argument was supplied."
I pinged the Splunk Indexer and found that it was using IPV6 to resolve the hostname. I disabled IPV6, then added the hostname IPV4 address in the localhosts file. Restarted Splunk and it is working fine now.

0 Karma

dstaulcu
Builder

I'm experiencing this problem too.. happening among all of my indexers and all of my heavy forwarders. Clients of each type are getting "WARN TcpOutputProc - Cooked connection to ip=x.x.x.x:9997 timed out". Problem continues even after upgrading from 6.0 and 6.0.3

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...