Getting Data In

TCP connection flowchart

MuS
SplunkTrust
SplunkTrust

Is there a TCP connection flowchart showing how the TCP connections are being established, controlled and closed between lightweight forwarder, heavy forwarder and indexer for 4.1.x?

Tags (1)
1 Solution

jrodman
Splunk Employee
Splunk Employee

Do you mean like a sequence diagram such as http://publib.boulder.ibm.com/infocenter/tpfhelp/current/topic/com.ibm.ztpf-ztpfdf.doc_put.cur/gtps5...

If so, the answer is no we do not.

I'm not sure the set of questions that you might have about forwarder sockets is really fully addressable via a sequence diagram. For an AutoLB situation there's a few behaviors that are interacting that I'm not sure how to visualize as a linear sequence. I suppose maybe i can do it as multiple vertical columns.

I think this is a good topic to document, and is not fully addressed currently. Maybe you can produce a sort of list of the kinds of things you would want to know. I have a list in my head already but I could miss some things.

You could log it as a 'support request', or mail me, or IM me and I'll make an internal doc item.

View solution in original post

jrodman
Splunk Employee
Splunk Employee

Do you mean like a sequence diagram such as http://publib.boulder.ibm.com/infocenter/tpfhelp/current/topic/com.ibm.ztpf-ztpfdf.doc_put.cur/gtps5...

If so, the answer is no we do not.

I'm not sure the set of questions that you might have about forwarder sockets is really fully addressable via a sequence diagram. For an AutoLB situation there's a few behaviors that are interacting that I'm not sure how to visualize as a linear sequence. I suppose maybe i can do it as multiple vertical columns.

I think this is a good topic to document, and is not fully addressed currently. Maybe you can produce a sort of list of the kinds of things you would want to know. I have a list in my head already but I could miss some things.

You could log it as a 'support request', or mail me, or IM me and I'll make an internal doc item.

MuS
SplunkTrust
SplunkTrust

just came to my mind, I still have to do this shameonme

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...