Fresh install of Splunk 4.2 on CentOS. I'm testing with one client but have also tried many. I'm using splunktcp-ssl using light forwarding from Linux and Windows. I am getting data but since going to 4.2 I'm seeing these errors every 30 seconds for each client sending cooked data. If I downgrade the server to 4.1.7 I see the same errors from the 4.2 forwarders.
03-17-2011 13:49:30.072 -0700 ERROR TcpInputProc - Error encountered for connection from src=xxx.xxx.xxx.34:37573. Success
03-17-2011 13:50:00.072 -0700 ERROR TcpInputProc - Error encountered for connection from src=xxx.xxx.xxx.34:37666. Success
03-17-2011 13:50:30.072 -0700 ERROR TcpInputProc - Error encountered for connection from src=xxx.xxx.xxx.34:37765. Success
Tweaking the heartbeat setting does not alter the 30 second timing.
Here is some DEBUG:
03-17-2011 12:41:07.871 DEBUG S2S - In doConsume for LengthReadingState
03-17-2011 12:41:07.871 DEBUG TcpChannel - Before accept
03-17-2011 12:41:07.871 DEBUG TcpChannel - Creating polled fd from factory
03-17-2011 12:41:07.871 DEBUG StatusMgr - Updating status for TcpInputProcessor
03-17-2011 12:41:07.871 INFO StatusMgr - destPort=9979, eventType=connect_done, sourceHost=xxx.xxx.xxx.34, sourceIp=xxx.xxx.xxx.34, sourcePort=57370, statusee=TcpInputProcessor
03-17-2011 12:41:07.871 INFO TcpInputConn - Connection in cooked mode from src=xxx.xxx.xxx.34:5737003-17-2011 12:41:07.872 DEBUG TcpChannel - adding connection to factory created fd = 0xa64e7860
03-17-2011 12:41:07.872 INFO TcpChannel - Accepted connection
03-17-2011 12:41:07.880 DEBUG StatusMgr - Updating status for TcpInputProcessor
03-17-2011 12:41:07.880 INFO StatusMgr - sourcePort=9979, ssl=true, statusee=TcpInputProcessor
03-17-2011 12:41:07.909 ERROR TcpInputProc - Error encountered for connection from src=xxx.xxx.xxx.34:57370. Success
03-17-2011 12:41:07.909 INFO TcpInputConn - src=xxx.xxx.xxx.34:57370 closed connection
03-17-2011 12:41:07.909 DEBUG StatusMgr - Updating status for TcpInputProcessor
03-17-2011 12:41:07.910 INFO StatusMgr - destPort=9979, eventType=connect_close, sourceHost=xxx.xxx.xxx.34, sourceIp=xxx.xxx.xxx.34, sourcePort=57370, statusee=TcpInputProcessor
And my input,output.conf:
[splunktcp-ssl:9979]
[SSL]
password = $1$+tCc8wYTRIqB
requireClientCert = false
rootCA = $SPLUNK_HOME/etc/auth/cacert.pem
serverCert = $SPLUNK_HOME/etc/auth/server.pem
[tcpout]
defaultGroup = Group1
[tcpout:Group1]
server = xxx.xxx.xxx.101:9979
[tcpout-server://xxx.xxx.xxx.101:9979]
sslCertPath = $SPLUNK_HOME/etc/auth/server.pem
sslPassword = $1$NPPqXQDYcSWN
sslRootCAPath = $SPLUNK_HOME/etc/auth/ca.pem
sslVerifyServerCert = false
... View more