Getting Data In

splunkd.log errors attempting to send PCF data via TCP

SPlunkQR
Explorer

Hello,

We are trying to send log data from PCF applications over to our Splunk indexers via TCP. This was configured and working fine on our old servers, but our new servers are throwing messages like:

06-24-2020 08:22:12.449 -0400 ERROR TcpInputProc - Message rejected. Received unexpected message of size=875640864 bytes from src=10.198.52.102:46154 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.

We tried setting it up using the steps outlined here: https://docs.cloudfoundry.org/devguide/services/integratsplue-splunk.html#config by copying over the rfc5424 installation from our old servers to the new servers. The link to the Splunk documentation does not appear to work anymore, but I was not able to find additional information about how to integrate w/ PCF with a quick search in Splunk.

We have the ports configured in our inputs.conf file like this:

[tcp://6001]
connection_host = dns
index = test
sourcetype = rfc5424_syslog

But we continue to see these error messages. Is there some additional configuration we should be checking to make sure it is configured to accept this TCP data correctly?

Thanks in advance for any assistance.

Labels (3)
Tags (4)
0 Karma

splunkcol
Builder

same problem here

 

08-05-2020 19:16:25.857 -0500 ERROR TcpInputProc - Message rejected. Received unexpected message of size=774796916 bytes from src=192.xxx.x.xx:64052 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...