Deployment Architecture

Indexer shows multiple CLOSE_WAIT sessions on 9997 with forwarders.

sgrey007
New Member

This is probably a follow up to the question asked 20 Mar '12, 02:49 by nebel.
ERROR TcpInputProc - Error encountered for connection
In the process of adding a number of new forwarders to our recently upgraded 5.0.2 (forwarders are still at 4.3.4) we noticed the same messages in splunkd.log on two of 5 indexers.
Further we see in netstat -a, numerous CLOSE_WAIT sessions with many forwarders new and old, forwarders, in some case multiple sessions to a forwarder.
The questions are, what causes it, and are there Splunk recommended TCP tweaks for Linux (CentOS/Redhat/Ubuntu) to resolve this system problem?

0 Karma

ekost
Splunk Employee
Splunk Employee

The symptoms you're describing are similar to a recent post here.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...