In my environment, there are two components like below.
Splunk 6.2.7 on Linux.
Splunk 6.2.7 on Windows 2008R2
Yesterday, when I checked
netstat on windows, Forwarder was creating about ten thousand sessions in status "TIME_WAIT", so couldn't create new sessions!
For now, it has been normal, because I've rebooted it.
But I am worried that it will happen again.
Why did it happen?
I checked splunkd.log, and I found so many
connection failed messages while it was happening.(I don't have any idea why the connection failed.)
If the connection between Splunk and Splunk forwarder has been failing for a long time, is that why it this happened?
I really appreciate if somebody can tell me about it.
I checked the answer below, but I don't configure
connection_host = dns, so I don't think that this cause applys to this phenomenon.