Getting Data In

Cisco ironport syslog broken pipe

sassens1
Path Finder

Hello

I configured Splunk to handle TCP syslog from ironport appliances:

[tcp://514]
connection_host = dns
index = ironport
source = mailinfra
sourcetype = cisco:esa:textmail
queueSize = 10MB

but there is quite a lot of alerts on ironport side:

Log Error: Subscription mrelay_mail_logs: Network error while sending log data to syslog server 10.91.2.3 (10.1.2.3): [Errno 32] Broken pipe

Ironport sends the logs on a VIP which is forwarder to a pool of Splunk Heavy Forwarders.

I'm gonna check if mulitples TCP sessions can be optimized on the loadbalancer but is there any specific Splunk inputs.conf parameter I should check as well? thanks.

hkhkgais
New Member

Same problem here ? May I know any solution that I can do ? thanks

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...