Hello Everyone, I need your help about a problem with Splunk HEC. I use the endpoint "event" to send logs into multiple HEC. I use Rsyslog (Omhttp) to send those logs. But I have a problem, each time I send logs to the HEC, this last one sent back a "FIN TCP" to my source server and close the TCP session . I set up my source server to send Keep-Alive TCP session between it and the HEC, but this parameter does not work. At each request, the HEC close the session and ignore the keep-alive. I try to apply this workaround "Solved: Splunk HEC closes connection instead of re-using i... - Splunk Community" but this is the same behaviour ... I need to understand why the HEC close TCP session all time, because I need to send my logs in HTTPS and with this behaviour, I have a TLS handshake at each log sent. Best regards, Shini
... View more