Getting Data In

How to resolve error "ERROR TcpInputProc - Error encountered for connection" on server?

rsingh
Explorer

i am getting 2 different errors on my Splunk server - please see attached for errors, unsure what is wrong

thanks for all your help

alt text

0 Karma
1 Solution

mattymo
Splunk Employee
Splunk Employee

Hi rsingh!

The tcpInputProc error about unknown protocol is usually due to the forwarder using a version of ssl that the indexer restricts..

Check the server.conf as per this doc:

https://docs.splunk.com/Documentation/Splunk/6.5.1/Security/SetyourSSLversion

Or ensure the certs being used are ok.

You can ensure your UF uses the right ssl version with sslVersions in outputs.conf

https://docs.splunk.com/Documentation/Splunk/6.5.1/Admin/Outputsconf

Your second error is simply search activity that contains the string error in it. You can filter that put by only searching source=*splunkd.log

- MattyMo

View solution in original post

mattymo
Splunk Employee
Splunk Employee

Hi rsingh!

The tcpInputProc error about unknown protocol is usually due to the forwarder using a version of ssl that the indexer restricts..

Check the server.conf as per this doc:

https://docs.splunk.com/Documentation/Splunk/6.5.1/Security/SetyourSSLversion

Or ensure the certs being used are ok.

You can ensure your UF uses the right ssl version with sslVersions in outputs.conf

https://docs.splunk.com/Documentation/Splunk/6.5.1/Admin/Outputsconf

Your second error is simply search activity that contains the string error in it. You can filter that put by only searching source=*splunkd.log

- MattyMo

rsingh
Explorer

thanks mmodestino - i think i resolved the previous errors but now i am getting a new one

ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-perfmon.exe"" splunk-perfmon - OutputHandler::composeOutput: Counter is not found: Page Faults/sec

rsingh
Explorer

thanks i fixed it

0 Karma

mattymo
Splunk Employee
Splunk Employee

Awesome! Glad you are up and working!

Could you share what you did to resolve the issue so that future readers can benefit?

- MattyMo
0 Karma

rsingh
Explorer

makes sure - i was able to click on the error itself and it showed me which server was having the error. looks like the server had an old output.conf splunk server

thanks again

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...