<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk forwarder not sending data to Indexer server in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-forwarder-not-sending-data-to-Indexer-server/m-p/689585#M19510</link>
    <description>&lt;P&gt;This could be a number of things causing issues, that said tcp ouput is normally something related to the network or setup.&lt;/P&gt;&lt;P&gt;A few things to check:&lt;/P&gt;&lt;P&gt;What does the inputs.conf look like on your indexer?&lt;/P&gt;&lt;P&gt;Check on the indexer the port - should show your configured port 9997&lt;BR /&gt;netstat -tupln&lt;/P&gt;&lt;P&gt;Is there a firewall blocking this port?&lt;/P&gt;&lt;P&gt;Can your UF communicate to Indexer?&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jun 2024 16:25:05 GMT</pubDate>
    <dc:creator>deepakc</dc:creator>
    <dc:date>2024-06-04T16:25:05Z</dc:date>
    <item>
      <title>Splunk forwarder not sending data to Indexer server</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-forwarder-not-sending-data-to-Indexer-server/m-p/689582#M19509</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;I have configured splunk forwarder and on which I am getting below error,&lt;BR /&gt;&lt;BR /&gt;WARN TcpOutputProc [8204 parsing] - The TCP output processor has paused the data flow. Forwarding to host_dest=WALVAU-VIDI-1 inside output group default-autolb-group from host_src=WALVAU-MCP-APP- has been blocked for blocked_seconds=400. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Task : I want to send data from Splunk forwarder to Splunk enterprise server ( Indexer )&lt;BR /&gt;&lt;BR /&gt;1.&amp;nbsp; I opened outbound port on UF 9997&lt;/P&gt;&lt;P&gt;2. Opened inbound port 9997 on indexer&lt;/P&gt;&lt;P&gt;outputs.conf on UF&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[tcpout]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;defaultGroup = default-autolb-group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[tcpout:default-autolb-group]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;server = WALVAU-VIDI-1:9997&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[tcpout-server://WALVAU-VIDI-1:9997]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;inputs.conf on UF&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;[monitor://D:\BEXT\Walmart_VAU_ACP\Log\BPI*.log]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = walmart_vau_acp&lt;BR /&gt;sourcetype = Walmart_VAU_ACP&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Please help me to fix the issue. So that forwarder will send data to Indexer server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 16:00:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-forwarder-not-sending-data-to-Indexer-server/m-p/689582#M19509</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-06-04T16:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder not sending data to Indexer server</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-forwarder-not-sending-data-to-Indexer-server/m-p/689585#M19510</link>
      <description>&lt;P&gt;This could be a number of things causing issues, that said tcp ouput is normally something related to the network or setup.&lt;/P&gt;&lt;P&gt;A few things to check:&lt;/P&gt;&lt;P&gt;What does the inputs.conf look like on your indexer?&lt;/P&gt;&lt;P&gt;Check on the indexer the port - should show your configured port 9997&lt;BR /&gt;netstat -tupln&lt;/P&gt;&lt;P&gt;Is there a firewall blocking this port?&lt;/P&gt;&lt;P&gt;Can your UF communicate to Indexer?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 16:25:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-forwarder-not-sending-data-to-Indexer-server/m-p/689585#M19510</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-06-04T16:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder not sending data to Indexer server</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-forwarder-not-sending-data-to-Indexer-server/m-p/689600#M19511</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) pls check if all good with license.. do you see any warnings/errors related to license?&lt;/P&gt;&lt;P&gt;2)&amp;nbsp;On the forwarder, pls check this:&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/bin/splunk btool outputs list --debug&lt;/P&gt;&lt;P&gt;3) On the indexer, pls check this:&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/bin/splunk btool inputs list --debug&lt;/P&gt;&lt;P&gt;(if $SPLUNK_HOME not setup properly, then add the exact path, like /opt/splunk)&lt;/P&gt;&lt;P&gt;4) from the UF, try to ping the indexer&lt;/P&gt;&lt;P&gt;5) from the UF, pls try to telnet the indexer at the receiving port&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 19:00:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-forwarder-not-sending-data-to-Indexer-server/m-p/689600#M19511</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-06-04T19:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder not sending data to Indexer server</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-forwarder-not-sending-data-to-Indexer-server/m-p/689781#M19547</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/79189"&gt;@deepakc&lt;/a&gt;&amp;nbsp;I have attached below screenshot and its showing the correct port opened and listening perfectly. Please validate at once.&lt;BR /&gt;&lt;BR /&gt;ON Indexer&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1717644894880.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31176i24E4044F09AE6716/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1717644894880.png" alt="uagraw01_0-1717644894880.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On UF&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_1-1717644916799.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31177iA7199CD7CEA5E2F7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_1-1717644916799.png" alt="uagraw01_1-1717644916799.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On indexer&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_2-1717644948995.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31178i21BFA7B6224E0BD6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_2-1717644948995.png" alt="uagraw01_2-1717644948995.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On UF&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_3-1717645067588.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31179iDFF4CD74618E3DBF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_3-1717645067588.png" alt="uagraw01_3-1717645067588.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 03:39:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-forwarder-not-sending-data-to-Indexer-server/m-p/689781#M19547</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-06-06T03:39:31Z</dc:date>
    </item>
  </channel>
</rss>

