Getting Data In

Why are universal forwarders reporting "Error in SSL_read = 10054" trying to forward data to our two intermediate heavy forwarders?

christeraustad
Explorer

Hi,

We have a Splunk cluster where we have 1400 hosts with Universal Forwarders installed. These UFs are forwarding to two intermediate Heavy Forwarders using SSL and load balancing. The hosts aren't sending a lot of data. I would guess on average 3-4kbps.

The problem we are seeing is that all of the hosts (UF) are experiencing SSL error 10054. Which basically means that the HF has dropped the connection.

09-07-2016 20:29:19.439 +0000 INFO  TcpOutputProc - Connection to XX.XX.XX.XX:9997 closed. default Error in SSL_read = 10054, SSL Error = error:00000000:lib(0):func(0):reason(0)

Has anyone experienced something similar? I guess I should mention that these hosts are connected to the network through a satellite link. Which means that latency and general network connectivity could also play a part in this.

0 Karma

Kieffer87
Communicator

Were you ever able to resolve this issue? I've got three UFs on a fairly high latency connection that report this error on a regular basis. I've implemented bandwidth restriction using limits.conf but still see the error logged.

0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

100054, means "Socket forcefully shut down by remote host"

I've a similar error message on some UFs and it looks like this is du to a network problem (ie a very short network cut that would force the TCP session to be reset (because of network unreachable returning to host for example that would immediately break the session)

but it is a generic network error so that's not the only possibility.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...