Getting Data In

Forwarder Port 9996 has intermittent connectivity issues since upgrading indexers to Splunk 4.3.2

balbano
Contributor

For some reason, ever since upgrading from 4.3.1 to 4.3.2, my 2 indexers have been experiencing intermittent connectivity issues with the default Forwarder Port TCP 9996.

They are taking turns doing this and I am afraid this can affect my client forwarder traffic down the line.

Anyone else having this problem.

I submitted a case to Splunk about this but wondering is anyone else is having this problem.

I know for sure this has never happened before and this started happening when I upgraded to 4.3.2

Let me know if theres anything I should do or look at to determine the issue.

Thanks.

Brian

0 Karma
1 Solution

balbano
Contributor

My issue was due to the indexers being overloaded due to failed time parsing.

I have corrected this and the performance has much improved.

I still think there is something different in the way that Splunk handled time parsing prior to 4.3.2 since I have never experienced these connection issues but Splunk Support helped me isolate the issue.

Thanks.
B

View solution in original post

0 Karma

balbano
Contributor

My issue was due to the indexers being overloaded due to failed time parsing.

I have corrected this and the performance has much improved.

I still think there is something different in the way that Splunk handled time parsing prior to 4.3.2 since I have never experienced these connection issues but Splunk Support helped me isolate the issue.

Thanks.
B

0 Karma

dantimola
Communicator

Please share what you've done to resolve the issue. Thanks.

0 Karma

christantoy
Path Finder

Can you explain how did you do it?? because i'll experiencing this last week till now..

0 Karma

balbano
Contributor

Is there no one having this issue?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...