Getting Data In

Cisco ironport syslog broken pipe

sassens1
Path Finder

Hello

I configured Splunk to handle TCP syslog from ironport appliances:

[tcp://514]
connection_host = dns
index = ironport
source = mailinfra
sourcetype = cisco:esa:textmail
queueSize = 10MB

but there is quite a lot of alerts on ironport side:

Log Error: Subscription mrelay_mail_logs: Network error while sending log data to syslog server 10.91.2.3 (10.1.2.3): [Errno 32] Broken pipe

Ironport sends the logs on a VIP which is forwarder to a pool of Splunk Heavy Forwarders.

I'm gonna check if mulitples TCP sessions can be optimized on the loadbalancer but is there any specific Splunk inputs.conf parameter I should check as well? thanks.

hkhkgais
New Member

Same problem here ? May I know any solution that I can do ? thanks

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

It’s go time — Boston, here we come!

Are you ready to take your Splunk skills to the next level? Get set, because Splunk University is back, and ...