Getting Data In

Splunk "destroying" a TCP connection

TheJagoff
Communicator

Hello. I noticed on a U/F, "Splunk destroying TcpOutputClient during shutdown/reload" as a level INFO and happens 4 or 5 times a minute for each of the 3 indexers.
The U/F has been running for quite some time and is not in a shutdown/reload situation and I am receiving events both _internal and OS data from the TA_Splunk_nix  from it.
Is destroying a connection a normal message and what would cause that? I can't seem to find anything online about this message.

Labels (2)
0 Karma
1 Solution

kiran_panchavat
SplunkTrust
SplunkTrust

@TheJagoff 

Please take a look. Is it related to the same?

Fixed issues - Splunk Documentation

Slow indexer/receiver detection capability - Splunk Community

Splunk crash during tcpout (outputs.conf) reload - Splunk Community

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

View solution in original post

kiran_panchavat
SplunkTrust
SplunkTrust

@TheJagoff 

Please take a look. Is it related to the same?

Fixed issues - Splunk Documentation

Slow indexer/receiver detection capability - Splunk Community

Splunk crash during tcpout (outputs.conf) reload - Splunk Community

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

TheJagoff
Communicator

Looking through the 2nd article that you suggested, it was noticed that the outputs.conf had 
autoLBFrequency = 15
forceTimebasedAutoLB = true

Removed forceTimebasedAutoLB = true and the message stopped after the U/F restarted. It appears that the 2 entries were conflicting with each other.

Thank you for the guidance!

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...