<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746872#M29498</link>
    <description>Usually process is that start to look from right to left and find first blocked / queue which is full. Then look the next processor of right hand side. Usually issue is there.</description>
    <pubDate>Fri, 23 May 2025 18:55:28 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2025-05-23T18:55:28Z</dc:date>
    <item>
      <title>Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746736#M29473</link>
      <description>&lt;P&gt;Hi splunkers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to understand a tricky point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using a distributed environment with 2 intermediate universal forwarders. They have to deal with 1.2 TB of data per day.&lt;/P&gt;&lt;P&gt;1 - Strangely, these UF have their parsing queues used (TOP 1 of the queues usage !) and these forwarders are UF !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 - These UF have 4 pipeline. If one of these pipeline parsing queue is full, the entire UF refuse connection from upstream forwarders.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There queues size where increased to 1GB (input / parsing / output ...). But sometimes, this situation comes back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you got any idea what could hapening ?&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 15:05:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746736#M29473</guid>
      <dc:creator>_olivier_</dc:creator>
      <dc:date>2025-05-22T15:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746738#M29474</link>
      <description>&lt;P&gt;Even you have defined several pipelines there are only one input pipeline for input processors. See &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.2/Indexer/Pipelinesets" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.2/Indexer/Pipelinesets&lt;/A&gt;&amp;nbsp;that could lead you a situation what you described.&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 15:20:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746738#M29474</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-05-22T15:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746753#M29475</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257739"&gt;@_olivier_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Increasing the queue size isnt a solution for this problem, all you are doing is introducing a risk that if that host fails that you will lose 1GB of buffered/queued date (per pipeline!), this should only be used for smoothing out short bursts of data.&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;has mentioned - having so many pipelines might not help you here, I believe an input will only make use of a single pipeline (whereas a pipeline can be be applied to multiple inputs).&amp;nbsp;&lt;/P&gt;&lt;P&gt;What kind of data are you sending to your UFs? Im suprised that the parsing queue is filling, as I wouldnt expect the UF to do much parsing. There is a change that its struggling to get the data out to the indexers, what is the connectivity like between the UFs and the indexers?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 16:08:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746753#M29475</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-22T16:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746755#M29476</link>
      <description>&lt;P&gt;Hi isoutamo,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the splunk doc, the is the description for in an out pipelines :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"When you enable multiple pipeline sets on a forwarder, each pipeline handles both data input and output."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Are you sure that only one line pipeline is affectied to input processor ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 16:26:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746755#M29476</guid>
      <dc:creator>_olivier_</dc:creator>
      <dc:date>2025-05-22T16:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746757#M29477</link>
      <description>&lt;P&gt;Hi Livehybrid&lt;/P&gt;&lt;P&gt;This pipelines configurations came from a splunk PS.&lt;/P&gt;&lt;P&gt;I understand the risk to loose 1 Gb of data if this forwarder goes down ! Thank you !&lt;/P&gt;&lt;P&gt;About the datas, all data is coming from upstreams forwarder. This is raw data (Firewall, DNS ...) and structured data as json entries.&lt;/P&gt;&lt;P&gt;The connectivity between f&amp;lt;dr and indexer is VPN (350 Mbps throughput for each forwarder).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A last point, i missed to wrote in my first post, We are in "y" double output&amp;nbsp; because we are mooving from one platform to a new one and during 1 month, we have to send data over the two platforms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 16:32:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746757#M29477</guid>
      <dc:creator>_olivier_</dc:creator>
      <dc:date>2025-05-22T16:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746771#M29481</link>
      <description>What I have read and understand based on many discussions is that even there is several pipelines those all share only one input part. I have gotten understanding that there is one input and pipelines start after that and it’s possible that this inputs will be blocked which also blocks other pipelines.</description>
      <pubDate>Thu, 22 May 2025 17:42:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746771#M29481</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-05-22T17:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746783#M29483</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257739"&gt;@_olivier_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I certainly don't doubt my PS colleagues in their recommendations, as they will certainly have more information that I do about this particular set up, but wanted to make sure you knew about the queue etc.&lt;/P&gt;&lt;P&gt;If its helpful, there is a really good explanation of pipelines at&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-many-pipelines-should-I-use-on-a-forwarder/m-p/410734" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-many-pipelines-should-I-use-on-a-forwarder/m-p/410734&lt;/A&gt;&amp;nbsp;which is worth a read.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interesting that you say about sending to two platforms, as it does sound like congestion outbound from the UF rather than an actual issue with the parsing part of the pipeline. It might be worth (if possible) monitoring the network egress to confirm its not hitting a ceiling, and also check if either of the two outputs are blocking (Check the _internal logs in both platforms for "TcpOutputProc" errors.&lt;/P&gt;&lt;P&gt;Another resource worth checking is&amp;nbsp;&lt;A href="https://conf.splunk.com/files/2019/slides/FN1570.pdf" target="_blank"&gt;https://conf.splunk.com/files/2019/slides/FN1570.pdf&lt;/A&gt;&amp;nbsp;which might also help.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 21:45:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746783#M29483</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-22T21:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746793#M29487</link>
      <description>When you have more than one target where you are sending then if any of those will blocked the traffic then all traffic will be blocked quite soon after that. Basically after blocked targets queue is full then all other targets will be blocked. This is default behavior of splunk. There are two options which you could change to change this behavior but it means that probability of lost some event will increase.</description>
      <pubDate>Thu, 22 May 2025 22:42:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746793#M29487</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-05-22T22:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746795#M29489</link>
      <description>You definitely should read what Harendra said!</description>
      <pubDate>Thu, 22 May 2025 22:44:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746795#M29489</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-05-22T22:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746818#M29495</link>
      <description>&lt;P class="lia-align-left"&gt;OK, this is the explanation of the connexions refused when one pipeline queue get blocked.&lt;/P&gt;&lt;P class="lia-align-left"&gt;Thanks,&lt;/P&gt;&lt;P class="lia-align-left"&gt;Now, I have to understand why i've got pipelines queues blocked.&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2025 06:02:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746818#M29495</guid>
      <dc:creator>_olivier_</dc:creator>
      <dc:date>2025-05-23T06:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746819#M29496</link>
      <description>&lt;P&gt;Thanks for the links, I gona read them and check logs for output errors.&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2025 06:05:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746819#M29496</guid>
      <dc:creator>_olivier_</dc:creator>
      <dc:date>2025-05-23T06:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Intermediate forwarders - queues blocked - TCP in refused for uptream forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746872#M29498</link>
      <description>Usually process is that start to look from right to left and find first blocked / queue which is full. Then look the next processor of right hand side. Usually issue is there.</description>
      <pubDate>Fri, 23 May 2025 18:55:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Intermediate-forwarders-queues-blocked-TCP-in-refused-for/m-p/746872#M29498</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-05-23T18:55:28Z</dc:date>
    </item>
  </channel>
</rss>

