Skip to main content

Cribl Stream UDP Ingestion Fails on Secondary Interfaces When rp_filter Is Enabled

  • September 28, 2026
  • 0 replies
  • 2 views

Jessica Bracken

Symptom

Cribl Stream ingests UDP data on one network interface but not another, even though packets arrive on both interfaces and the Source listens on 0.0.0.0.

Environment

  • Cribl Stream self-managed Worker on Linux
  • UDP or Raw UDP Source
  • Worker with multiple network interfaces
  • Source Address configured as 0.0.0.0

Resolution

  1. Identify the network interfaces that receive the UDP traffic.
    ip -br address
  2. Verify the reverse-path filtering value for each affected interface.
    sysctl net.ipv4.conf.<interface>.rp_filter
  3. Disable reverse-path filtering on each affected interface.
    sudo sysctl -w net.ipv4.conf.<interface>.rp_filter=0
  4. Repeat the configuration for every affected interface.
  5. Send test UDP data to each interface IP address.
  6. Verify that Cribl Stream ingests the test data from each interface.
  7. Persist the interface-specific setting in the host’s system configuration if it must survive a restart.

Cause

This can be caused by:

  • Linux reverse-path filtering in strict mode (rp_filter=1) rejecting packets whose return route does not use the receiving interface.
  • Asymmetric routing on a multi-interface Worker causing valid UDP packets to fail the interface-specific reverse-path check.

Additional Information

  • Setting only net.ipv4.conf.all.rp_filter=0 might not resolve the issue. Configure the affected interfaces explicitly.
  • Binding a Source to 0.0.0.0 allows it to listen on all local addresses, but it does not override Linux interface-level packet filtering.
  • For Source configuration details, see the UDP (Raw) Source documentation.