Getting Data In

How to resolve "tcp-rst-from-server" & "tcp-rst-from-client" errors?

yossefn
Path Finder

Hi, 

I'm trying to collect logs from a web servers, but getting an error on the FIrewall says "tcp-rst-from-server" on port 9997. Also, I have another error "tcp-rst-from-client" on port 8089.

I have to say that there are other servers in the same VLAN that I'm getting logs from. 

Where can I look to solve the problem?

Labels (1)
0 Karma

sbaror11
Explorer

Is it a question about Splunk or about the web servers? 

tcp reset from client or from servers is a layer-2 error which refers to an application layer related event

It can be described as "the client or server terminated the session but I don't know why"

You can look at the application (http/https) logs to see the reason. 

0 Karma

yossefn
Path Finder

Hi @sbaror11

The question is about Splunk - wondered if maybe Splunk denied somehow the connection, or I missed some configuration that preventing me from getting the logs. 

I had kind of issue with "aged-out" errors on the FW logs, then I figured out that the local FW on the Splunk servers denied the connection. 

0 Karma

kgalibert
New Member

Hi,

Do you have find your solution?

Have same issue between an UF on Windows server AD and an UF Relay.

Thans

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...