Deployment Architecture

ERROR TcpChannel - Error trying to begin socket accept: An invalid argument was supplied.

alane
Engager

Upgraded Deployment Server / License Server to Version 6. Runs OK for 15 minutes then maxes out CPU and starts to fail with
ERROR TcpChannel - Error trying to begin socket accept: An invalid argument was supplied.
showing in SplunkD log.

Voltaire
Communicator

Are you using IPV6?
I had a similar issue with Splunk 6.0 build 182037. "ERROR TcpChannel - Error trying to begin socket accept: An invalid argument was supplied."
I pinged the Splunk Indexer and found that it was using IPV6 to resolve the hostname. I disabled IPV6, then added the hostname IPV4 address in the localhosts file. Restarted Splunk and it is working fine now.

0 Karma

dstaulcu
Builder

I'm experiencing this problem too.. happening among all of my indexers and all of my heavy forwarders. Clients of each type are getting "WARN TcpOutputProc - Cooked connection to ip=x.x.x.x:9997 timed out". Problem continues even after upgrading from 6.0 and 6.0.3

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...