Monitoring Splunk

We have observed one error from one forwarder server to indexer.

satkan100
Path Finder

We have observed one error from one forwarder server to indexer.
Error Message:08-20-2018 13:34:39.963 +0200 ERROR TcpInputProc - Message rejected. Received unexpected 842019128 byte message! from src=192.168.1.71:37694. Maximum message allowed: 67108864. (::)

Tags (1)
0 Karma

CarsonZa
Contributor

double check your ports. Obviously you can change these but, deployment over 8089 and forwarding over 9997. these should be the same through out your environment.

0 Karma

satkan100
Path Finder

i am having issue in only one forwarder showing this issue remaining working fine .In our environment we dont use Deployment server.

0 Karma

CarsonZa
Contributor

is this a uf or a heavy forwarder

0 Karma

satkan100
Path Finder

THIS IS UF & Forwarder SERVER OS is UNIX.

0 Karma

satkan100
Path Finder

That Forwader is UF & Forwarder Server Os environment is Unix .

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...