<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder Stop Sending Data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stop-sending-data/m-p/585559#M103006</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234014"&gt;@JuanAntunes&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Couple reasons for this issue&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please check if any queues are filling on the UF side , due to some sources sending too much data at once.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;and any network issue between UF and HF , check in splunkd.log for timeout issues and check from the HF side as well.&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;also in splunkd.log check for any ERROR or WARN error&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;when we faced same issue, it turnout to be intermittent networks issues caused,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;in your case it might be same issue or new one&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Feb 2022 13:09:22 GMT</pubDate>
    <dc:creator>SanjayReddy</dc:creator>
    <dc:date>2022-02-17T13:09:22Z</dc:date>
    <item>
      <title>Why does universal forwarder stop sending data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stop-sending-data/m-p/585548#M103004</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;&lt;BR /&gt;I have an environment with about 200 machines, all Windows Servers. All servers are sending TCP information through port 9997 directly to my Heavy Forwarder, all information is allocated in the "Windows" index&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What happens is that about 1-2x a day, the logs sent by Universal Forwarders stop from all machines&amp;nbsp;leaving the Windows index blank.&amp;nbsp;All other data that do not arrive through TCP 9997 are normal, such as some scripts that bring other types of information and save in other indexes.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The problem is only solved when Splunk is restarted in Heavy Forwarder&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Trying to diagnose the problem, the only thing I could find is this message on all servers with Universal Forwarder installed&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;02-16-2022 15:20:51.293 -0400 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been blocked for 82200 seconds&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;Has anyone gone through something similar, or can help me try to identify what is happening?&lt;BR /&gt;Remembering that the Log in Heavy Forwader, doesn't bring me anything relevant&lt;BR /&gt;&lt;BR /&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 16:11:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stop-sending-data/m-p/585548#M103004</guid>
      <dc:creator>JuanAntunes</dc:creator>
      <dc:date>2022-02-17T16:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Stop Sending Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stop-sending-data/m-p/585556#M103005</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234014"&gt;@JuanAntunes&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;some additional information:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;have you used the correct reference hardware for your HF?&lt;/LI&gt;&lt;LI&gt;which other jobs are scheduled in your Heavy Forwarder?&lt;/LI&gt;&lt;LI&gt;are you sure that, when forwardring stops, there isn't any job that usues the available bandwidth?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;it seems that sometimes, when a scheduled job starts, your forwarding stops.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 13:04:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stop-sending-data/m-p/585556#M103005</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-02-17T13:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Stop Sending Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stop-sending-data/m-p/585559#M103006</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234014"&gt;@JuanAntunes&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Couple reasons for this issue&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please check if any queues are filling on the UF side , due to some sources sending too much data at once.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;and any network issue between UF and HF , check in splunkd.log for timeout issues and check from the HF side as well.&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;also in splunkd.log check for any ERROR or WARN error&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;when we faced same issue, it turnout to be intermittent networks issues caused,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;in your case it might be same issue or new one&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 13:09:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stop-sending-data/m-p/585559#M103006</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2022-02-17T13:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Stop Sending Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stop-sending-data/m-p/585582#M103009</link>
      <description>&lt;P&gt;Use &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/DMC/DMCoverview" target="_self"&gt;DMC&lt;/A&gt;&amp;nbsp;to see what's going on with HF. UF logs suggest that HF (as defined in outputs.conf for stanza&amp;nbsp;&lt;EM&gt;default-autolb-group&lt;/EM&gt;) is down/unavailable causing data ingestion to stop. Use "&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/DMC/IndexingDeployment" target="_self"&gt;Indexing Performance&lt;/A&gt;" dashboards in DMC to see if any queues are getting filled up.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 15:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stop-sending-data/m-p/585582#M103009</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2022-02-17T15:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Stop Sending Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stop-sending-data/m-p/585584#M103010</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;you obviously have blocked queues at least on HF side maybe even idx side too. Easy way to look what it situation on HF side is add it as an indexer with e.g. IHF custom group defined into MC. Then you can easily look what are happening on those queues and pipelines on that (and another nodes). If you haven't MC on place yet, then I strongly recommend to set it up.&lt;/P&gt;&lt;P&gt;Here are two excellent conf presentation how to look the situation even without MC.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://conf.splunk.com/files/2019/slides/FN1570.pdf" target="_blank"&gt;https://conf.splunk.com/files/2019/slides/FN1570.pdf&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://conf.splunk.com/files/2019/slides/FN1402.pdf" target="_blank"&gt;https://conf.splunk.com/files/2019/slides/FN1402.pdf&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://github.com/silkyrich/cluster_health_tools" target="_blank"&gt;https://github.com/silkyrich/cluster_health_tools&lt;/A&gt;&amp;nbsp;(git repo for previous presentation)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 15:07:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stop-sending-data/m-p/585584#M103010</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-02-17T15:07:27Z</dc:date>
    </item>
  </channel>
</rss>

