Getting Data In

UF tries to open two connections at the same time on the same outbound port

sgarvin55
Splunk Employee
Splunk Employee

On several servers, the universal forwarder tries to open up two connections at the same time on the same outbound port. The first connection succeeds, and the second connection generates event id 5157 for splunkd.exe. This happens constantly all day. How can I correct this to stop generating these errors?

Tags (2)
1 Solution

sgarvin55
Splunk Employee
Splunk Employee

We checked the following as possible causes for this issue:

  1. outputs.conf for multiple entries using same port
  2. more than one instance of Splunk running
  3. Firewall issues
  4. Event Logs show:

Audit Failure 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5157 Filtering Platform Connection
Audit Success 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5156 Filtering Platform Connection
Audit Failure 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5157 Filtering Platform Connection
Audit Success 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5156 Filtering Platform Connection

The issues was fixed by this Microsoft KB article:

http://support.microsoft.com/kb/2654852

View solution in original post

sgarvin55
Splunk Employee
Splunk Employee

We checked the following as possible causes for this issue:

  1. outputs.conf for multiple entries using same port
  2. more than one instance of Splunk running
  3. Firewall issues
  4. Event Logs show:

Audit Failure 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5157 Filtering Platform Connection
Audit Success 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5156 Filtering Platform Connection
Audit Failure 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5157 Filtering Platform Connection
Audit Success 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5156 Filtering Platform Connection

The issues was fixed by this Microsoft KB article:

http://support.microsoft.com/kb/2654852

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...