Refine your search:

Hoping someone can help me out here:

I have a system with a heavy forwarder installed (v.4.1.6) that shows the following event repeatedly (at last count 150k+)

10-06-2011 17:56:33.846 WARN  TcpOutputProc - The event is missing source information. Event :

I think it has something to do with a bad input the configurations are standardized an look correct. I have also reinstalled the splunk package with no luck. Connectivity between the client and the indexer is OK ; I can port 9997 is open and clear.


asked 06 Oct '11, 11:11

Kate_Lawrence-Gupta's gravatar image

accept rate: 7%

edited 06 Oct '11, 16:03

dwaddle's gravatar image

dwaddle ♦

One Answer:

Kate - am not sure this may solve it - but have you checked that host's IP address and / or name are set up correctly? Probably a daft question if its a major server out there ;-)


answered 26 Sep '12, 06:01

DaveSavage's gravatar image

accept rate: 8%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions



Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported



Asked: 06 Oct '11, 11:11

Seen: 1,111 times

Last updated: 26 Sep '12, 06:01

Copyright © 2005-2014 Splunk Inc. All rights reserved.