<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding stopped suddenly for few of the forwarders in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591699#M12031</link>
    <description>&lt;P&gt;I had restarted splunkd in one of the affected forwarders .Here&amp;nbsp; is the log flow of splunkd.log&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;splunkd.log&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;&lt;U&gt;Just before shutdown&amp;nbsp;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;03-28-2022 11:24:23.074 +0100 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group index_peers has been blocked for &lt;FONT color="#FF0000"&gt;9989240&lt;/FONT&gt; &lt;FONT color="#FF0000"&gt;seconds&lt;/FONT&gt;. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;03-28-2022 11:24:33.085 +0100 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group index_peers has been blocked for &lt;FONT color="#FF0000"&gt;9989250 seconds.&lt;/FONT&gt; This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;03-28-2022 11:24:37.798 +0100 INFO PipelineComponent - Performing early shutdown tasks&lt;BR /&gt;03-28-2022 11:24:37.798 +0100 INFO IndexProcessor - handleSignal : Disabling streaming searches.&lt;BR /&gt;03-28-2022 11:24:37.798 +0100 INFO IndexProcessor - request state change from=RUN to=SHUTDOWN_SIGNALED&lt;BR /&gt;03-28-2022 11:24:37.798 +0100 INFO loader - Shutdown HTTPDispatchThread&lt;BR /&gt;03-28-2022 11:24:37.798 +0100 INFO ShutdownHandler - &lt;FONT color="#FF6600"&gt;Shutting down splunkd&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;U&gt;starting splunkd&amp;nbsp;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;03-28-2022 11:25:40.952 +0100 INFO loader - &lt;FONT color="#00FF00"&gt;Splunkd starting (build be11b2c46e23).&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;03-28-2022 11:25:46.164 +0100 INFO TcpOutputProc - Will resolve indexer names at 450.000 second interval.&lt;BR /&gt;03-28-2022 11:25:46.589 +0100 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;03-28-2022 11:25:46.614 +0100 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;&lt;BR /&gt;03-28-2022 11:26:11.164 +0100 INFO TcpOutputProc - Initialization time for indexer discovery service for default group=index_peers has been completed.&lt;BR /&gt;03-28-2022 11:26:11.212 +0100 INFO ScheduledViewsReaper - Scheduled views reaper run complete. Reaped count=0 scheduled views&lt;BR /&gt;03-28-2022 11:26:11.215 +0100 INFO TailReader - Continuing...&lt;BR /&gt;03-28-2022 11:26:11.215 +0100 INFO TailReader - ...continuing.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;FONT color="#FF6600"&gt;Again "&amp;nbsp;TcpOutputProc" start appearing - reset with 10 seconds&amp;nbsp;&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;03-28-2022 11:26:11.411 +0100 WARN TcpOutputProc - Applying quarantine to ip=xx.yy.zz.aa&amp;nbsp; port=xxxx _numberOfFailures=2&lt;BR /&gt;03-28-2022 11:26:21.036 +0100 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group index_peers has been &lt;FONT color="#FF0000"&gt;blocked for 10 seconds&lt;/FONT&gt;. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;03-28-2022 11:26:21.218 +0100 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;03-28-2022 11:26:21.218 +0100 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;03-28-2022 11:26:31.047 +0100 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group index_peers has been &lt;FONT color="#FF0000"&gt;blocked for 20 seconds&lt;/FONT&gt;. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 31 Mar 2022 06:39:19 GMT</pubDate>
    <dc:creator>yj055</dc:creator>
    <dc:date>2022-03-31T06:39:19Z</dc:date>
    <item>
      <title>Why has the Forwarding stopped suddenly for few of the forwarders?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591416#M11992</link>
      <description>&lt;P&gt;We have a distributed architecture&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Search head cluster with 6 hosts across 3 data centres&lt;/P&gt;
&lt;P&gt;Index cluster with 6 index peers and 1 index master&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Forwarders on all servers in environment&amp;nbsp; - web tier, app tier, load balancer tier&lt;/P&gt;
&lt;P&gt;Few months back , web tier stopped sending - log stopped coming to splunk ; but other tiers are are working&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When checked the activity on web-tier , there was a patching happened and splunkd was restarted -after that forwarding stopped in web-tier&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But splunkd process came up fine - still running in those&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And observed below WARN messages started coming exactly same time&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[ See the highlighted in &lt;FONT color="#FF0000"&gt;red&lt;/FONT&gt; starting from 10 seconds it grows ]&lt;/P&gt;
&lt;P&gt;WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group index_peers has been &lt;FONT color="#FF0000"&gt;blocked for 10 seconds.&lt;/FONT&gt; This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;
&lt;P&gt;----------&lt;/P&gt;
&lt;P&gt;------&lt;/P&gt;
&lt;P&gt;+0000 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group index-peers has been &lt;FONT color="#FF0000"&gt;blocked for 9725460 seconds.&lt;/FONT&gt; This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;+0000 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group index-peers has been &lt;FONT color="#FF0000"&gt;blocked for 9725470 seconds.&lt;/FONT&gt; This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;=============================================================================&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Why we picked this WARN message may be cause - as same happened in other tier recently&amp;nbsp;&lt;/P&gt;
&lt;P&gt;load lancer tier stopped stopped forwarding recently. Above WARN started showing&amp;nbsp; same time onwards - starting with&amp;nbsp;&amp;nbsp;&lt;FONT color="#FF0000"&gt;"blocked for 10 seconds&amp;nbsp; "&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;&lt;FONT color="#000000"&gt;splunk forwarder is running fine in all these&amp;nbsp;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT color="#000000"&gt;App tier still working -sending data , so indexers are fine&amp;nbsp;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT color="#000000"&gt;not disk space or memory issue in any of these&amp;nbsp;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT color="#000000"&gt;No config changes done any where ( inputs or outputs conf or any file that matter) -its same , just that stopped working suddenly&amp;nbsp;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;What could have caused this sudden stopping of forwarding ?&lt;/FONT&gt;&lt;/P&gt;
&lt;H4&gt;Splunk Enterprise&lt;/H4&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Version:7.2.1Build:be11b2c46e23&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 16:13:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591416#M11992</guid>
      <dc:creator>yj055</dc:creator>
      <dc:date>2022-03-30T16:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding stopped suddenly for few of the forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591489#M12001</link>
      <description>&lt;P&gt;This sounds more of a network connectivity problem...&lt;/P&gt;&lt;P&gt;Are you able to test port 9997 on the affected forwarders to ensure it's open?&lt;/P&gt;&lt;P&gt;Could it be that these affected servers are on a different VLAN?&lt;/P&gt;&lt;P&gt;Are the indexers listed in your outputs.conf listed as FQDNs or IPs? Can you run the nslookup command on those indexers from your forwarders?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 12:37:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591489#M12001</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-03-30T12:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding stopped suddenly for few of the forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591515#M12006</link>
      <description>&lt;P&gt;We couldn't observe any connectivity issue as such. As I mentioned it's only few forwarders stopped working .Rest of the forwarders still sending data to same set of index clusters&lt;/P&gt;&lt;P&gt;And the port we use is 8089 , which is open&amp;nbsp;&lt;/P&gt;&lt;P&gt;splunkuser@fwdernode system]$ telnet idxnode1.iuser.iroot.adidom.com 8089&lt;BR /&gt;Trying xx.yy.zz.aa...&lt;BR /&gt;Connected to idxnode1.iuser.iroot.adidom.com.&lt;BR /&gt;Escape character is '^]'.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;outputs.conf&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;defaultGroup = index_peers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Indexers listed as&amp;nbsp;index_peers&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;server.conf&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on each indexer node 1&lt;/P&gt;&lt;P&gt;[general]&lt;BR /&gt;serverName = node1_idx01&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;server.conf&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on each indexer node 2&lt;/P&gt;&lt;P&gt;[general]&lt;BR /&gt;serverName = node2_idx01&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 14:03:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591515#M12006</guid>
      <dc:creator>yj055</dc:creator>
      <dc:date>2022-03-30T14:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding stopped suddenly for few of the forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591548#M12010</link>
      <description>&lt;P&gt;Thank you that's helpful.&lt;/P&gt;&lt;P&gt;Can you read splunkd.log while you restart the splunkforwarder service on the affected machines. What does it say before it starts saying "&lt;SPAN&gt;Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group index-peers has been blocked"?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 15:11:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591548#M12010</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-03-30T15:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding stopped suddenly for few of the forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591699#M12031</link>
      <description>&lt;P&gt;I had restarted splunkd in one of the affected forwarders .Here&amp;nbsp; is the log flow of splunkd.log&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;splunkd.log&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;&lt;U&gt;Just before shutdown&amp;nbsp;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;03-28-2022 11:24:23.074 +0100 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group index_peers has been blocked for &lt;FONT color="#FF0000"&gt;9989240&lt;/FONT&gt; &lt;FONT color="#FF0000"&gt;seconds&lt;/FONT&gt;. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;03-28-2022 11:24:33.085 +0100 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group index_peers has been blocked for &lt;FONT color="#FF0000"&gt;9989250 seconds.&lt;/FONT&gt; This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;03-28-2022 11:24:37.798 +0100 INFO PipelineComponent - Performing early shutdown tasks&lt;BR /&gt;03-28-2022 11:24:37.798 +0100 INFO IndexProcessor - handleSignal : Disabling streaming searches.&lt;BR /&gt;03-28-2022 11:24:37.798 +0100 INFO IndexProcessor - request state change from=RUN to=SHUTDOWN_SIGNALED&lt;BR /&gt;03-28-2022 11:24:37.798 +0100 INFO loader - Shutdown HTTPDispatchThread&lt;BR /&gt;03-28-2022 11:24:37.798 +0100 INFO ShutdownHandler - &lt;FONT color="#FF6600"&gt;Shutting down splunkd&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;U&gt;starting splunkd&amp;nbsp;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;03-28-2022 11:25:40.952 +0100 INFO loader - &lt;FONT color="#00FF00"&gt;Splunkd starting (build be11b2c46e23).&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;03-28-2022 11:25:46.164 +0100 INFO TcpOutputProc - Will resolve indexer names at 450.000 second interval.&lt;BR /&gt;03-28-2022 11:25:46.589 +0100 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;03-28-2022 11:25:46.614 +0100 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;&lt;BR /&gt;03-28-2022 11:26:11.164 +0100 INFO TcpOutputProc - Initialization time for indexer discovery service for default group=index_peers has been completed.&lt;BR /&gt;03-28-2022 11:26:11.212 +0100 INFO ScheduledViewsReaper - Scheduled views reaper run complete. Reaped count=0 scheduled views&lt;BR /&gt;03-28-2022 11:26:11.215 +0100 INFO TailReader - Continuing...&lt;BR /&gt;03-28-2022 11:26:11.215 +0100 INFO TailReader - ...continuing.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;FONT color="#FF6600"&gt;Again "&amp;nbsp;TcpOutputProc" start appearing - reset with 10 seconds&amp;nbsp;&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;03-28-2022 11:26:11.411 +0100 WARN TcpOutputProc - Applying quarantine to ip=xx.yy.zz.aa&amp;nbsp; port=xxxx _numberOfFailures=2&lt;BR /&gt;03-28-2022 11:26:21.036 +0100 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group index_peers has been &lt;FONT color="#FF0000"&gt;blocked for 10 seconds&lt;/FONT&gt;. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;03-28-2022 11:26:21.218 +0100 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;03-28-2022 11:26:21.218 +0100 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;03-28-2022 11:26:31.047 +0100 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group index_peers has been &lt;FONT color="#FF0000"&gt;blocked for 20 seconds&lt;/FONT&gt;. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 06:39:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591699#M12031</guid>
      <dc:creator>yj055</dc:creator>
      <dc:date>2022-03-31T06:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding stopped suddenly for few of the forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591776#M12037</link>
      <description>&lt;P&gt;This has me stumped.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244398"&gt;@yj055&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;&lt;U&gt;&lt;FONT color="#FF6600"&gt;Again "&amp;nbsp;TcpOutputProc" start appearing - reset with 10 seconds&amp;nbsp;&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;03-28-2022 11:26:11.411 +0100 WARN TcpOutputProc - Applying quarantine to ip=xx.yy.zz.aa&amp;nbsp; port=xxxx _numberOfFailures=2&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Was this one of the correct IP/port combinations for your indexer or are you using indexer discovery?&lt;/P&gt;&lt;P&gt;ip=xx.yy.zz.aa port=xxxx&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe you can try to completely uninstall the forwarder and reinstall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 13:34:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591776#M12037</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-03-31T13:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding stopped suddenly for few of the forwarders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591792#M12038</link>
      <description>&lt;P&gt;Yes , they are the correct IP and port of&amp;nbsp; the indexer&lt;/P&gt;&lt;P&gt;the log message are&amp;nbsp; there for all the index peers&amp;nbsp; with correct receiver port (means have multiple occurrences of below log for each of the indexer ip and port )&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;03-28-2022 11:26:11.411 +0100 WARN TcpOutputProc - Applying quarantine to ip=xx.yy.zz.aa&amp;nbsp; port=xxxx _numberOfFailures=2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As I had&amp;nbsp;&lt;/SPAN&gt;mentioned initial post , the entire set web tier forwarders stopped working few months back&amp;nbsp;&lt;/P&gt;&lt;P&gt;Load balancer tier forwarder was working then until last week . LB forwarders stopped , splunkd log started showing same WARN messages&amp;nbsp;&lt;SPAN&gt;TcpOutputProc"&amp;nbsp; :&amp;nbsp; tcpout Processor: The TCP output processor has paused the data flow&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I see the same messages in the console health notification as well&amp;nbsp; as&amp;nbsp;&amp;nbsp;"&amp;nbsp;TCPOutAutoLB-0"&amp;nbsp; warning&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we would like to know what had caused all these&amp;nbsp; production forwarders to stop suddenly before we decide and plan for fresh install&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Like more may stop , as of now application tier forwarders are still working - those source types still giving data&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 14:30:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-has-the-Forwarding-stopped-suddenly-for-few-of-the/m-p/591792#M12038</guid>
      <dc:creator>yj055</dc:creator>
      <dc:date>2022-03-31T14:30:35Z</dc:date>
    </item>
  </channel>
</rss>

