Getting Data In

Cisco ironport syslog broken pipe

sassens1
Path Finder

Hello

I configured Splunk to handle TCP syslog from ironport appliances:

[tcp://514]
connection_host = dns
index = ironport
source = mailinfra
sourcetype = cisco:esa:textmail
queueSize = 10MB

but there is quite a lot of alerts on ironport side:

Log Error: Subscription mrelay_mail_logs: Network error while sending log data to syslog server 10.91.2.3 (10.1.2.3): [Errno 32] Broken pipe

Ironport sends the logs on a VIP which is forwarder to a pool of Splunk Heavy Forwarders.

I'm gonna check if mulitples TCP sessions can be optimized on the loadbalancer but is there any specific Splunk inputs.conf parameter I should check as well? thanks.

hkhkgais
New Member

Same problem here ? May I know any solution that I can do ? thanks

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...