Symptom
Cribl Stream ingests UDP data on one network interface but not another, even though packets arrive on both interfaces and the Source listens on 0.0.0.0.
Environment
- Cribl Stream self-managed Worker on Linux
- UDP or Raw UDP Source
- Worker with multiple network interfaces
- Source Address configured as
0.0.0.0
Resolution
- Identify the network interfaces that receive the UDP traffic.
ip -br address - Verify the reverse-path filtering value for each affected interface.
sysctl net.ipv4.conf.<interface>.rp_filter - Disable reverse-path filtering on each affected interface.
sudo sysctl -w net.ipv4.conf.<interface>.rp_filter=0 - Repeat the configuration for every affected interface.
- Send test UDP data to each interface IP address.
- Verify that Cribl Stream ingests the test data from each interface.
- Persist the interface-specific setting in the host’s system configuration if it must survive a restart.
Cause
This can be caused by:
- Linux reverse-path filtering in strict mode (
rp_filter=1) rejecting packets whose return route does not use the receiving interface. - Asymmetric routing on a multi-interface Worker causing valid UDP packets to fail the interface-specific reverse-path check.
Additional Information
- Setting only
net.ipv4.conf.all.rp_filter=0might not resolve the issue. Configure the affected interfaces explicitly. - Binding a Source to
0.0.0.0allows it to listen on all local addresses, but it does not override Linux interface-level packet filtering. - For Source configuration details, see the UDP (Raw) Source documentation.
