Getting Data In

Forwarder Port 9996 has intermittent connectivity issues since upgrading indexers to Splunk 4.3.2

balbano
Contributor

For some reason, ever since upgrading from 4.3.1 to 4.3.2, my 2 indexers have been experiencing intermittent connectivity issues with the default Forwarder Port TCP 9996.

They are taking turns doing this and I am afraid this can affect my client forwarder traffic down the line.

Anyone else having this problem.

I submitted a case to Splunk about this but wondering is anyone else is having this problem.

I know for sure this has never happened before and this started happening when I upgraded to 4.3.2

Let me know if theres anything I should do or look at to determine the issue.

Thanks.

Brian

0 Karma
1 Solution

balbano
Contributor

My issue was due to the indexers being overloaded due to failed time parsing.

I have corrected this and the performance has much improved.

I still think there is something different in the way that Splunk handled time parsing prior to 4.3.2 since I have never experienced these connection issues but Splunk Support helped me isolate the issue.

Thanks.
B

View solution in original post

0 Karma

balbano
Contributor

My issue was due to the indexers being overloaded due to failed time parsing.

I have corrected this and the performance has much improved.

I still think there is something different in the way that Splunk handled time parsing prior to 4.3.2 since I have never experienced these connection issues but Splunk Support helped me isolate the issue.

Thanks.
B

0 Karma

dantimola
Communicator

Please share what you've done to resolve the issue. Thanks.

0 Karma

christantoy
Path Finder

Can you explain how did you do it?? because i'll experiencing this last week till now..

0 Karma

balbano
Contributor

Is there no one having this issue?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...