Getting Data In

SplunkForwarder flooding splunkd.log with reconnect errors

yachtbum
Loves-to-Learn

After upgrading to splunkforwarder 9.4.5 we noticed that SplunkForwarder.service gets panic when loosing connection to its endpoint.

splunkd.log gets flooded with these messages:
 
10-10-2025 14:22:48.336 +0100 ERROR TcpOutputFd [234730 TcpOutEloop] - Connection to host=xx.xx.xx.xx:xxxx failed
10-10-2025 14:22:48.337 +0100 WARN  TcpOutputFd [234730 TcpOutEloop] - Connect to xx.xx.xx.xx:xxxx failed. Connection refused

When doing a count in the logfile it looks like the forwarder tries to reconnect about 5000 times every second.

Anyone else noticed this behaviour?
Is it possible to configure the reconnect retry timeout to make the forwarder more relaxed ? 


 

Labels (1)
0 Karma

shashankD
Explorer

Increase maxkbps value to 0 (unlimited) and maxThruput to 5mb, this will resolve the issue

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@yachtbum - This is true in some environments. I notice so many of these warnings. Not sure exact root cause.

Although you cannot currently configure the reconnect retry timeout in Splunk. 

But you can configure the normal connection timeout setting in outputs.conf on the forwarder if that is what you need for your environment.

VatsalJagani_0-1762608518763.pngVatsalJagani_0-1762608518763.png

 

I hope this helps!!! Kindly upvote if it does!!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...