Knowledge Management

SPL-74902 and SPL-76208, do I have to upgrade Indexer, Forwarder or both?

anderius
Explorer

Description: "In environments with malware and end-point scanning activities occurring, some network events can cause Splunk to generate TcpChannel - Error trying to begin socket accept: An invalid argument was supplied. messages in splunkd.log. (SPL-74902, SPL-76208)"

This is fixed in 6.0.1, but it is not clear for me if I have to upgrade the indexer, the forwarder, or both?

The question of "indexer, forwarder or both" applies to everything in the release notes, but it is this specific issue that interests me right now.

Tags (1)
1 Solution

anderspdmt
Engager

I did encounter the problem again after upgrading only the server, so I guess the answer is yes. It would be nice to have information like this from a more official source, though...

View solution in original post

0 Karma

anderspdmt
Engager

I did encounter the problem again after upgrading only the server, so I guess the answer is yes. It would be nice to have information like this from a more official source, though...

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...