<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HF doesn't accept traffic from UF in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575214#M101668</link>
    <description>&lt;P&gt;From the technical point of view - you don't have to.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.3/Admin/Wheretofindtheconfigurationfiles" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.3/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It's just that if you don't keep your configs "tidy", they can get confusing quickly with settings being spread all over the place &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hmm... but if you have splunktcp input and you can see TLS handshake over the wire then UF must be applying some TLS settings and trying to negotiate secure connection.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Nov 2021 08:22:13 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-11-17T08:22:13Z</dc:date>
    <item>
      <title>HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574906#M101599</link>
      <description>&lt;P&gt;Hi Splunk chaps,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm facing problem with feeding HF from UF (HF is sending data to the cloud and this works fine).&amp;nbsp; I can exclude network or firewall issue - both servers are reachable from opposite side.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is a chunk of log errors from UF :&amp;nbsp;&lt;/P&gt;&lt;P&gt;11-15-2021 11:12:57.024 +0000 INFO DC:DeploymentClient [6735 PhonehomeThread] - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;11-15-2021 11:13:09.024 +0000 INFO DC:DeploymentClient [6735 PhonehomeThread] - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;11-15-2021 11:13:10.140 +0000 WARN HttpPubSubConnection [6734 HttpClientPollingThread_97C72192-9F2D-4883-830A-776376593AC1] - Unable to parse message from PubSubSvr:&lt;BR /&gt;11-15-2021 11:13:10.140 +0000 INFO HttpPubSubConnection [6734 HttpClientPollingThread_97C72192-9F2D-4883-830A-776376593AC1] - Could not obtain connection, will retry after=70.985 seconds.&lt;BR /&gt;11-15-2021 11:13:17.695 +0000 WARN TcpOutputProc [3551 parsing] - The TCP output processor has paused the data flow. Forwarding to host_dest=172.23.11.216 inside output group default-autolb-group from host_src=ldcrapnvvip10 has been blocked for blocked_seconds=446600. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;&lt;P&gt;Please see output debug from UF.&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/splunkforwarder/etc/system/default/outputs.conf [syslog]&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf maxEventSize = 1024&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf priority = &amp;lt;13&amp;gt;&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf type = udp&lt;BR /&gt;/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/outputs.conf [tcpout]&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf ackTimeoutOnShutdown = 30&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf autoLBFrequency = 30&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf autoLBVolume = 0&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf blockOnCloning = true&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf blockWarnThreshold = 100&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256:AES128-SHA256:ECDH-ECDSA-AES256-GCM-SHA384:ECDH-ECDSA-AES128-GCM-SHA256:ECDH-ECDSA-AES256-SHA384:ECDH-ECDSA-AES128-SHA256&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf compressed = false&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf connectionTTL = 0&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf connectionTimeout = 20&lt;BR /&gt;/opt/splunkforwarder/etc/system/local/outputs.conf defaultGroup = default-autolb-group&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf disabled = false&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf dropClonedEventsOnQueueFull = 5&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf dropEventsOnQueueFull = -1&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf ecdhCurves = prime256v1, secp384r1, secp521r1&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf forceTimebasedAutoLB = false&lt;BR /&gt;/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/outputs.conf forwardedindex.0.whitelist = .*&lt;BR /&gt;/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/outputs.conf forwardedindex.1.blacklist = _.*&lt;BR /&gt;/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/outputs.conf forwardedindex.2.whitelist = (_audit|_introspection|_internal|_telemetry)&lt;BR /&gt;/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/outputs.conf forwardedindex.filter.disable = false&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf heartbeatFrequency = 30&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf indexAndForward = false&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf maxConnectionsPerIndexer = 2&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf maxFailuresPerInterval = 2&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf maxQueueSize = auto&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf readTimeout = 300&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf secsInFailureInterval = 1&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf sendCookedData = true&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf sslQuietShutdown = false&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf sslVersions = tls1.2&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf tcpSendBufSz = 0&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf useACK = false&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf useClientSSLCompression = true&lt;BR /&gt;/opt/splunkforwarder/etc/system/default/outputs.conf writeTimeout = 300&lt;BR /&gt;/opt/splunkforwarder/etc/system/local/outputs.conf [tcpout-server://172.23.11.216:9997]&lt;BR /&gt;/opt/splunkforwarder/etc/system/local/outputs.conf [tcpout:default-autolb-group]&lt;BR /&gt;/opt/splunkforwarder/etc/system/local/outputs.conf disabled = false&lt;BR /&gt;/opt/splunkforwarder/etc/system/local/outputs.conf server = 172.23.11.216:9997&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what blocks it?&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance,&lt;/P&gt;&lt;P&gt;Sz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 11:54:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574906#M101599</guid>
      <dc:creator>slipinski</dc:creator>
      <dc:date>2021-11-15T11:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574907#M101600</link>
      <description>&lt;P&gt;Below is input config of HF.&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/system/default/inputs.conf [SSL]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf allowSslRenegotiation = true&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf ecdhCurves = prime256v1, secp384r1, secp521r1&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = default&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf sslQuietShutdown = false&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf sslVersions = tls1.2&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [batch:///opt/splunk/var/run/splunk/search_telemetry/*search_telemetry.json]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = _introspection&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf log_on_completion = 0&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf move_policy = sinkhole&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf sourcetype = search_telemetry&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [batch:///opt/splunk/var/spool/splunk]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = default&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf move_policy = sinkhole&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [batch:///opt/splunk/var/spool/splunk/...stash_hec]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = default&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf move_policy = sinkhole&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf sourcetype = stash_hec&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [batch:///opt/splunk/var/spool/splunk/...stash_new]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = default&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf move_policy = sinkhole&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf queue = stashparsing&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf sourcetype = stash_new&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf time_before_close = 0&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [batch:///opt/splunk/var/spool/splunk/tracker.log*]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = _internal&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf move_policy = sinkhole&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf sourcetype = splunkd_latency_tracker&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [blacklist:/opt/splunk/etc/auth]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = default&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [blacklist:/opt/splunk/etc/passwd]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = default&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [fschange:/opt/splunk/etc]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf delayInMills = 100&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf disabled = false&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf filesPerDelay = 10&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf followLinks = false&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf fullEvent = false&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf hashMaxSize = -1&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = default&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf pollPeriod = 600&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf recurse = true&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf sendEventMaxSize = -1&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf signedaudit = true&lt;BR /&gt;/opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf [http]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf ackIdleCleanup = true&lt;BR /&gt;/opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf allowSslCompression = true&lt;BR /&gt;/opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf allowSslRenegotiation = true&lt;BR /&gt;/opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf dedicatedIoThreads = 2&lt;BR /&gt;/opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf disabled = 1&lt;BR /&gt;/opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf enableSSL = 1&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = default&lt;BR /&gt;/opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf maxSockets = 0&lt;BR /&gt;/opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf maxThreads = 0&lt;BR /&gt;/opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf port = 8088&lt;BR /&gt;/opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf sslVersions = *,-ssl2&lt;BR /&gt;/opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf useDeploymentServer = 0&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [monitor:///opt/splunk/etc/splunk.version]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _TCP_ROUTING = *&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = _internal&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf sourcetype = splunk_version&lt;BR /&gt;/opt/splunk/etc/apps/introspection_generator_addon/default/inputs.conf [monitor:///opt/splunk/var/log/introspection]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/apps/introspection_generator_addon/default/inputs.conf index = _introspection&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [monitor:///opt/splunk/var/log/splunk]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = _internal&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [monitor:///opt/splunk/var/log/splunk/license_usage_summary.log]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = _telemetry&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [monitor:///opt/splunk/var/log/splunk/splunk_instrumentation_cloud.log*]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = _telemetry&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf sourcetype = splunk_cloud_telemetry&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [monitor:///opt/splunk/var/log/watchdog/watchdog.log*]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = _internal&lt;BR /&gt;/opt/splunk/etc/apps/search/local/inputs.conf [monitor:///var/log/secure]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/apps/search/local/inputs.conf disabled = false&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/apps/search/local/inputs.conf index = discol&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf [script]&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf host = $decideOnStartup&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf index = default&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf interval = 60.0&lt;BR /&gt;/opt/splunk/etc/system/default/inputs.conf start_by_shell = true&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 11:56:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574907#M101600</guid>
      <dc:creator>slipinski</dc:creator>
      <dc:date>2021-11-15T11:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574908#M101601</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/124273"&gt;@slipinski&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;a very stupid question:&lt;/P&gt;&lt;P&gt;did you enabled Receiving [Settings -- Forwarding and Receiving -- Receiving] and Forwarding [Settings -- Forwarding and Receiving -- Forwarding] on the HFs?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 12:04:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574908#M101601</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-15T12:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574912#M101602</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;.&amp;nbsp;I think I did, but currently doesn't have access to webgui. Can I confirm these settings in CLI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Sz&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 12:24:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574912#M101602</guid>
      <dc:creator>slipinski</dc:creator>
      <dc:date>2021-11-15T12:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574917#M101603</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/124273"&gt;@slipinski&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you can check receiving vieving in $SPLUNK_HOME/etc/system/local/inputs.conf if you have the stanza&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[splunktcp://9997]
disabled = 0&lt;/LI-CODE&gt;&lt;P&gt;you can check forwarding&amp;nbsp; vieving in $SPLUNK_HOME/etc/system/local/outputs.conf if you have the stanza&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[tcpout]
defaultGroup=my_indexers

[tcpout:my_indexers]
server=mysplunk_indexer1:9997, mysplunk_indexer2:9996

[tcpout-server://mysplunk_indexer1:9997]&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 13:04:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574917#M101603</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-15T13:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574932#M101604</link>
      <description>&lt;P&gt;Either input and output seem to be ok.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 14:28:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574932#M101604</guid>
      <dc:creator>slipinski</dc:creator>
      <dc:date>2021-11-15T14:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574934#M101605</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/124273"&gt;@slipinski&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you checked local firewalls (iptables) on HFs?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 14:33:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574934#M101605</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-15T14:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574935#M101606</link>
      <description>&lt;P&gt;Yes, I allowed traffic on these 3 ports, just to be on safe side&lt;/P&gt;&lt;P&gt;firewall-cmd --zone=public --permanent --add-port=8000/tcp&lt;BR /&gt;firewall-cmd --zone=public --permanent --add-port=9997/tcp&lt;BR /&gt;firewall-cmd --zone=public --permanent --add-port=8089/tcp&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 14:36:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574935#M101606</guid>
      <dc:creator>slipinski</dc:creator>
      <dc:date>2021-11-15T14:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574936#M101607</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/124273"&gt;@slipinski&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;using Telnet on one Universal Forwarder, what does it happen if you run:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;telnet &amp;lt;HF_IP_Address&amp;gt; 9997&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 14:39:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574936#M101607</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-15T14:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574937#M101608</link>
      <description>&lt;P&gt;It works.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 14:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574937#M101608</guid>
      <dc:creator>slipinski</dc:creator>
      <dc:date>2021-11-15T14:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574939#M101609</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/124273"&gt;@slipinski&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;what does it happen if you run the following searches on your Splunk Cloud:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=&amp;lt;hostname_Heavy_Forwarder&amp;gt;
index=_internal host=&amp;lt;hostname_Universal_Forwarder&amp;gt;
index=* host=&amp;lt;hostname_Universal_Forwarder&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;if you haven't results, probablky the problem is in the connection between HFs and Splunk Cloud.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 14:47:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574939#M101609</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-15T14:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574940#M101610</link>
      <description>&lt;P&gt;I added one logfile to being monitored under HF and can see results in a cloud.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 14:51:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574940#M101610</guid>
      <dc:creator>slipinski</dc:creator>
      <dc:date>2021-11-15T14:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574942#M101611</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/124273"&gt;@slipinski&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;what does it happen if you run the above searches on Splunk Cloud?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 15:21:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/574942#M101611</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-15T15:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575000#M101620</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_internal host=&amp;lt;hostname_Heavy_Forwarder&amp;gt;  OK
index=_internal host=&amp;lt;hostname_Universal_Forwarder&amp;gt; Nothing
index=* host=&amp;lt;hostname_Universal_Forwarder&amp;gt; Nothing&lt;/LI-CODE&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp; Only data from HF are visible in the cloud.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 08:03:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575000#M101620</guid>
      <dc:creator>slipinski</dc:creator>
      <dc:date>2021-11-16T08:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575006#M101621</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/124273"&gt;@slipinski&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;ok, summarizing the analysis:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;HF data are sent to Cloud,&lt;/LI&gt;&lt;LI&gt;UF data aren't sent to Cloud (both internal and external data),&lt;/LI&gt;&lt;LI&gt;firewall routes between UFs and HFs are open (telnet test),&lt;/LI&gt;&lt;LI&gt;HFs are open to receive data,&lt;/LI&gt;&lt;LI&gt;UFs have the correct outputs.conf (addressing the HFs in outputs.conf).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The strange thing is that you haven't neither _internal and external logs from UFs.&lt;/P&gt;&lt;P&gt;Could you share the outputs.conf and inputs.conf of UFs?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 08:37:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575006#M101621</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-16T08:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575008#M101622</link>
      <description>&lt;PRE&gt;[tcpout]&lt;BR /&gt;defaultGroup = default-autolb-group&lt;BR /&gt;&lt;BR /&gt;[tcpout:default-autolb-group]&lt;BR /&gt;disabled = false&lt;BR /&gt;server = 172.23.11.216:9997&lt;BR /&gt;&lt;BR /&gt;[tcpout-server://172.23.11.216:9997]&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;172.23.11.216 is obviously address of HW.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 08:45:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575008#M101622</guid>
      <dc:creator>slipinski</dc:creator>
      <dc:date>2021-11-16T08:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575012#M101623</link>
      <description>&lt;P&gt;If you cannot found nothing from HFs logs related to UF connections then I propose that it's time for tcpdump to check if there is any traffic towards HF.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 09:13:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575012#M101623</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-16T09:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575023#M101628</link>
      <description>&lt;P&gt;Yes, there is. However, HF replys to UF with [RST,ACK] packets. This generally means that port is closed, but in reality it isn't. As I mentioned before, I can telnet to HF on port 8089.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 11:46:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575023#M101628</guid>
      <dc:creator>slipinski</dc:creator>
      <dc:date>2021-11-16T11:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575026#M101629</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/124273"&gt;@slipinski&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please try telnet on port 9997.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 11:57:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575026#M101629</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-16T11:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: HF doesn't accept traffic from UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575029#M101631</link>
      <description>&lt;P&gt;Exactly. That's the first step with any connection problems. Dump the traffic on the appropriate interface and see whether any connection tries even take place.&lt;/P&gt;&lt;P&gt;tcpdump/wireshark is your greatest friend with network/connection troubleshooting.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 12:33:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-doesn-t-accept-traffic-from-UF/m-p/575029#M101631</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-16T12:33:35Z</dc:date>
    </item>
  </channel>
</rss>

