<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Applying Quarantine  .... Removing quarantine in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117921#M22928</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;
I have a UF in which Splunk_TA_nix application is installed and it was working fine but suddenly it started giving these errors in splunkd.log which causes discountinuty of sending the data to the Indexers.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;02-03-2015 12:05:39.119 +0100 INFO  TailingProcessor - Could not send data to output queue (parsingQueue), retrying...
02-03-2015 12:05:50.632 +0100 WARN  TcpOutputProc - Cooked connection to ip=XXXXXXXXXXX:9997 timed out
02-03-2015 12:05:56.872 +0100 INFO  ExecProcessor - Ran script: /opt/SP/apps/splunkforwarder/Splunkforwarder-5.0/etc/apps/Splunk_TA_nix/bin/ps.sh, took 74.28 milliseconds to run, 11510 bytes read
02-03-2015 12:05:57.594 +0100 INFO  ExecProcessor - Ran script: /opt/SP/apps/splunkforwarder/Splunkforwarder-5.0/etc/apps/Splunk_TA_nix/bin/cpu.sh, took 1043.8 milliseconds to run, 1003 bytes read
02-03-2015 12:06:00.636 +0100 WARN  TcpOutputFd - Connect to XXXXXX:9997 failed. Connection refused
02-03-2015 12:06:00.636 +0100 ERROR TcpOutputFd - Connection to host=XXXXXXXXXXX:9997 failed
02-03-2015 12:06:00.636 +0100 WARN  TcpOutputProc - Applying quarantine to ip=XXXXXXXX port=9997 _numberOfFailures=2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have an outputs.conf which  is as follows :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = AABBCCDD:9997
useACK=true
sendCookedData = true


[tcpout-server://AABBCCDD:9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note : AABBCCDD is the load balancer server ip&lt;/P&gt;

&lt;P&gt;Data is appearing in the dashboard but not in the continous manner, it is missing for last 3 hours , sometimes it is missing for last 30 mins. Please HELP !!&lt;/P&gt;

&lt;P&gt;Cheers,&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 18:46:32 GMT</pubDate>
    <dc:creator>abhayneilam</dc:creator>
    <dc:date>2020-09-28T18:46:32Z</dc:date>
    <item>
      <title>Applying Quarantine  .... Removing quarantine</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117921#M22928</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I have a UF in which Splunk_TA_nix application is installed and it was working fine but suddenly it started giving these errors in splunkd.log which causes discountinuty of sending the data to the Indexers.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;02-03-2015 12:05:39.119 +0100 INFO  TailingProcessor - Could not send data to output queue (parsingQueue), retrying...
02-03-2015 12:05:50.632 +0100 WARN  TcpOutputProc - Cooked connection to ip=XXXXXXXXXXX:9997 timed out
02-03-2015 12:05:56.872 +0100 INFO  ExecProcessor - Ran script: /opt/SP/apps/splunkforwarder/Splunkforwarder-5.0/etc/apps/Splunk_TA_nix/bin/ps.sh, took 74.28 milliseconds to run, 11510 bytes read
02-03-2015 12:05:57.594 +0100 INFO  ExecProcessor - Ran script: /opt/SP/apps/splunkforwarder/Splunkforwarder-5.0/etc/apps/Splunk_TA_nix/bin/cpu.sh, took 1043.8 milliseconds to run, 1003 bytes read
02-03-2015 12:06:00.636 +0100 WARN  TcpOutputFd - Connect to XXXXXX:9997 failed. Connection refused
02-03-2015 12:06:00.636 +0100 ERROR TcpOutputFd - Connection to host=XXXXXXXXXXX:9997 failed
02-03-2015 12:06:00.636 +0100 WARN  TcpOutputProc - Applying quarantine to ip=XXXXXXXX port=9997 _numberOfFailures=2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have an outputs.conf which  is as follows :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = AABBCCDD:9997
useACK=true
sendCookedData = true


[tcpout-server://AABBCCDD:9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note : AABBCCDD is the load balancer server ip&lt;/P&gt;

&lt;P&gt;Data is appearing in the dashboard but not in the continous manner, it is missing for last 3 hours , sometimes it is missing for last 30 mins. Please HELP !!&lt;/P&gt;

&lt;P&gt;Cheers,&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:46:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117921#M22928</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2020-09-28T18:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Applying Quarantine  .... Removing quarantine</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117922#M22929</link>
      <description>&lt;P&gt;Hi abhayneilam,&lt;/P&gt;

&lt;P&gt;usually there was a change somewhere, If something suddenly stops working. &lt;BR /&gt;
Check this load-balancer or the Server OS, because &lt;CODE&gt;Connection refused&lt;/CODE&gt; means that the target machine actively rejected the connection.&lt;BR /&gt;
Check any fire wall in between, also consider routing settings.&lt;BR /&gt;
Don't forget to check if splunkd is running on the indexers....&lt;/P&gt;

&lt;P&gt;May I ask, why are you not using the universal forwarders internal load-balancing method?&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 11:51:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117922#M22929</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-02-03T11:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: Applying Quarantine  .... Removing quarantine</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117923#M22930</link>
      <description>&lt;P&gt;We have this configured from the past 1 year, so all fine , no issues until yesterday, suddenly I dont know, Quantine issue appears : &lt;/P&gt;

&lt;P&gt;02-03-2015 09:47:19.246 +0100 INFO  TcpOutputProc - Removing quarantine from idx=XXXXX:9997&lt;BR /&gt;
02-03-2015 09:47:39.247 +0100 WARN  TcpOutputProc - Cooked connection to ip=XXXXX:9997 timed out&lt;BR /&gt;
02-03-2015 09:47:39.248 +0100 WARN  TcpOutputProc - Cooked connection to ip=XXXXX:9997 timed out&lt;BR /&gt;
02-03-2015 09:47:39.248 +0100 WARN  TcpOutputProc - Cooked connection to ip=XXXXX:9997 timed out&lt;BR /&gt;
02-03-2015 09:47:39.248 +0100 WARN  TcpOutputProc - Applying quarantine to ip=XXXXX port=9997 _numberOfFailures=2&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 12:05:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117923#M22930</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2015-02-03T12:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Applying Quarantine  .... Removing quarantine</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117924#M22931</link>
      <description>&lt;P&gt;so what did change yesterday? You're obviously no longer able to connect to port 9997 on IP XXXXX&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 12:10:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117924#M22931</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-02-03T12:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Applying Quarantine  .... Removing quarantine</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117925#M22932</link>
      <description>&lt;P&gt;Nothing was changed !! that's why it is strange , suddenly it happened.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 13:23:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117925#M22932</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2015-02-03T13:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Applying Quarantine  .... Removing quarantine</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117926#M22933</link>
      <description>&lt;P&gt;Did you ever resolve this issue? If so, how?&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 16:44:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Applying-Quarantine-Removing-quarantine/m-p/117926#M22933</guid>
      <dc:creator>mmensch</dc:creator>
      <dc:date>2016-05-04T16:44:48Z</dc:date>
    </item>
  </channel>
</rss>

