Installation

splunkd: Read operation timed out expecting ACK from x.x.x.x:9997 in 300 seconds

tcador
New Member

Hello,

Seeing this WARN log message roughly every 1-2 minutes on forwarders sending logs with ACK enabled to two separate indexers.

WARN TcpOutputProc - Read operation timed out expecting ACK from x.x.x.x:9997 in 300 seconds.

Also seeing these around the same time: TcpOutputProc - Possible duplication of events with channel=source::my_source_file_path|host::my_host_name|encrypted|49628, streamId=1484623843723112376, offset=32768 on host=x.x.x.x:9997

I am also seeing about 5% duplication of events.

Tags (3)
0 Karma

lguinn2
Legend

Well, yes - you would see duplication because this message means the forwarder is saying "I am not getting the acknowledgement that is required, so I am resending the data".

So I would check the connectivity between the forwarders and this host. I would also look at the host to see what problems it is having.

lguinn2
Legend

Is one or more of the indexers out of disk space? Overloaded and hanging?

If it isn't a network issue, and you don't see performance problems of any kind on the server, I would open a support ticket.

0 Karma

tcador
New Member

I should have mentioned this in the original question. I have checked/verified connectivity between the forwarder and indexer and do not see any issues. Are there any configurations on either end that I could be missing?

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...