Getting Data In

Windows Universal Forwarder Duplication Events

fabiocaldas
Contributor

I work with UniversalForwarders (136 servers) sending data to a Heavy Forwarder Cluster (3 servers) that forward data to a Splunk Indexer (1 server).

On the 3 servers layers it's set useAck=true on configs.

I have just one windows server where I'm facing the following error.

12-30-2013 19:58:30.063 +0000 INFO TcpOutputProc - Connection to x.x.x.x:9997 closed. Read error. An existing connection was forcibly closed by the remote host.

12-30-2013 19:58:30.063 +0000 WARN TcpOutputProc - Possible duplication of events with channel=source::WinEventLog:Application|host::i-83f142a3|WinEventLog:Application|0, streamId=704141485450455387, offset=111562 on host=x.x.x.x:9997

12-30-2013 19:58:30.063 +0000 WARN TcpOutputProc - Possible duplication of events with channel=source::C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log|host::i-83f142a3|splunkd|30, streamId=0, offset=0 on host=x.x.x.x:9997

The others 135 servers are ok, just one is giving this error.

Any suggestion?

0 Karma

fabiocaldas
Contributor

Yes linu1988, few seconds after restart my universal forwarder start to give me the same error message.

0 Karma

lukejadamec
Super Champion

Hello,

It sounds like it might be a network issue. Here is a good document that describes the use of useACK, and describes a number of causes for the error you're getting.

http://docs.splunk.com/Documentation/Splunk/6.0.1/Forwarding/Protectagainstlossofin-flightdata

0 Karma

linu1988
Champion

Did you try to restart the forwarder?

0 Karma

fabiocaldas
Contributor

Now I have 3 servers facing same problem

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...