Getting Data In

UF tries to open two connections at the same time on the same outbound port

sgarvin55
Splunk Employee
Splunk Employee

On several servers, the universal forwarder tries to open up two connections at the same time on the same outbound port. The first connection succeeds, and the second connection generates event id 5157 for splunkd.exe. This happens constantly all day. How can I correct this to stop generating these errors?

Tags (2)
1 Solution

sgarvin55
Splunk Employee
Splunk Employee

We checked the following as possible causes for this issue:

  1. outputs.conf for multiple entries using same port
  2. more than one instance of Splunk running
  3. Firewall issues
  4. Event Logs show:

Audit Failure 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5157 Filtering Platform Connection
Audit Success 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5156 Filtering Platform Connection
Audit Failure 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5157 Filtering Platform Connection
Audit Success 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5156 Filtering Platform Connection

The issues was fixed by this Microsoft KB article:

http://support.microsoft.com/kb/2654852

View solution in original post

sgarvin55
Splunk Employee
Splunk Employee

We checked the following as possible causes for this issue:

  1. outputs.conf for multiple entries using same port
  2. more than one instance of Splunk running
  3. Firewall issues
  4. Event Logs show:

Audit Failure 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5157 Filtering Platform Connection
Audit Success 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5156 Filtering Platform Connection
Audit Failure 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5157 Filtering Platform Connection
Audit Success 6/10/2013 10:08:37 AM Microsoft Windows security auditing. 5156 Filtering Platform Connection

The issues was fixed by this Microsoft KB article:

http://support.microsoft.com/kb/2654852

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...