All Apps and Add-ons

How do you fix a Stream TCP reassembly queue overflow?

joeldavideng
Path Finder

The Splunk Stream forwarders on my two primary DNS servers are failing every couple of hours for a TCP reassembly queue overflow. I tried doubling the queue size and filtering out all internal DNS traffic, but the agents still shutdown daily. Has anyone dealt with this before and know what settings to tweak?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...