Getting Data In

Forwarder Port 9996 has intermittent connectivity issues since upgrading indexers to Splunk 4.3.2

balbano
Contributor

For some reason, ever since upgrading from 4.3.1 to 4.3.2, my 2 indexers have been experiencing intermittent connectivity issues with the default Forwarder Port TCP 9996.

They are taking turns doing this and I am afraid this can affect my client forwarder traffic down the line.

Anyone else having this problem.

I submitted a case to Splunk about this but wondering is anyone else is having this problem.

I know for sure this has never happened before and this started happening when I upgraded to 4.3.2

Let me know if theres anything I should do or look at to determine the issue.

Thanks.

Brian

0 Karma
1 Solution

balbano
Contributor

My issue was due to the indexers being overloaded due to failed time parsing.

I have corrected this and the performance has much improved.

I still think there is something different in the way that Splunk handled time parsing prior to 4.3.2 since I have never experienced these connection issues but Splunk Support helped me isolate the issue.

Thanks.
B

View solution in original post

0 Karma

balbano
Contributor

My issue was due to the indexers being overloaded due to failed time parsing.

I have corrected this and the performance has much improved.

I still think there is something different in the way that Splunk handled time parsing prior to 4.3.2 since I have never experienced these connection issues but Splunk Support helped me isolate the issue.

Thanks.
B

0 Karma

dantimola
Communicator

Please share what you've done to resolve the issue. Thanks.

0 Karma

christantoy
Path Finder

Can you explain how did you do it?? because i'll experiencing this last week till now..

0 Karma

balbano
Contributor

Is there no one having this issue?

0 Karma
Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...