Monitoring Splunk

Splunk Indexer Error

abhijitnath89ax
Loves-to-Learn

We received the below error in splunkd.log on our indexer server. We are using cluster env with 6 indexers. The indexers are coming up and down

11-05-2020 07:23:03.304 +0000 ERROR TcpInputProc - Error encountered for connection from src=X.X.X.X:60116. Broken pipe
Labels (2)
0 Karma

nwuest
Path Finder

Hi @abhijitnath89ax,

After doing some researching about the error you have depicted could be related to the indexers trying to see if the others indexers/receivers are "alive" named a heartbeat function.

View solution in original post by @hliakathali_spl 

 

Would there happen to be a firewall change either in the network and/or a firewall change on the Splunk Indexers themselves that are prohibiting the connection between them?

 
We hope to hear back from you!
 
V/R,
nwuest
0 Karma
Get Updates on the Splunk Community!

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and Splunk ES Protecting a ...

It's Customer Success Time at .conf25

Hello Splunkers,   Ready for .conf25? The customer success and experience team is and can’t wait to see you ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...