Getting Data In

How to resolve "tcp-rst-from-server" & "tcp-rst-from-client" errors?

yossefn
Path Finder

Hi, 

I'm trying to collect logs from a web servers, but getting an error on the FIrewall says "tcp-rst-from-server" on port 9997. Also, I have another error "tcp-rst-from-client" on port 8089.

I have to say that there are other servers in the same VLAN that I'm getting logs from. 

Where can I look to solve the problem?

Labels (1)
0 Karma

sbaror11
Explorer

Is it a question about Splunk or about the web servers? 

tcp reset from client or from servers is a layer-2 error which refers to an application layer related event

It can be described as "the client or server terminated the session but I don't know why"

You can look at the application (http/https) logs to see the reason. 

0 Karma

yossefn
Path Finder

Hi @sbaror11

The question is about Splunk - wondered if maybe Splunk denied somehow the connection, or I missed some configuration that preventing me from getting the logs. 

I had kind of issue with "aged-out" errors on the FW logs, then I figured out that the local FW on the Splunk servers denied the connection. 

0 Karma

kgalibert
New Member

Hi,

Do you have find your solution?

Have same issue between an UF on Windows server AD and an UF Relay.

Thans

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...