In my environment, there are two components like below.
Splunk 6.2.7 on Linux.
Splunk 6.2.7 on Windows 2008R2
Yesterday, when I checked netstat
on windows, Forwarder was creating about ten thousand sessions in status "TIME_WAIT", so couldn't create new sessions!
For now, it has been normal, because I've rebooted it.
But I am worried that it will happen again.
Why did it happen?
I checked splunkd.log, and I found so many connection failed
messages while it was happening.(I don't have any idea why the connection failed.)
If the connection between Splunk and Splunk forwarder has been failing for a long time, is that why it this happened?
I really appreciate if somebody can tell me about it.
I checked the answer below, but I don't configure connection_host = dns
, so I don't think that this cause applys to this phenomenon.
https://answers.splunk.com/answers/114447/splunk-to-splunk-communication-stuck-in-close-wait.html
How is your indexing performance? Did you take a look at your indexer splunkd.log ?