Getting Data In

UF tries to open two connections at the same time on the same outbound port

sgarvin55
Splunk Employee
Splunk Employee

On several servers, the universal forwarder tries to open up two connections at the same time on the same outbound port. The first connection succeeds, and the second connection generates event id 5157 for splunkd.exe. This happens constantly all day. How can I correct this to stop generating these errors?

Tags (2)
1 Solution

sgarvin55
Splunk Employee
Splunk Employee

We checked the following as possible causes for this issue:

  1. outputs.conf for multiple entries using same port
  2. more than one instance of Splunk running
  3. Firewall issues
  4. Event Logs show:

Audit Failure 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5157 Filtering Platform Connection
Audit Success 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5156 Filtering Platform Connection
Audit Failure 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5157 Filtering Platform Connection
Audit Success 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5156 Filtering Platform Connection

The issues was fixed by this Microsoft KB article:

http://support.microsoft.com/kb/2654852

View solution in original post

sgarvin55
Splunk Employee
Splunk Employee

We checked the following as possible causes for this issue:

  1. outputs.conf for multiple entries using same port
  2. more than one instance of Splunk running
  3. Firewall issues
  4. Event Logs show:

Audit Failure 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5157 Filtering Platform Connection
Audit Success 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5156 Filtering Platform Connection
Audit Failure 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5157 Filtering Platform Connection
Audit Success 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5156 Filtering Platform Connection

The issues was fixed by this Microsoft KB article:

http://support.microsoft.com/kb/2654852

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...