<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Forwarder: Stops sending data after Too Many Fields in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606917#M105410</link>
    <description>&lt;P&gt;What is telling you why the forwarder stops sending data?&amp;nbsp; What error message(s) do you get?&lt;/P&gt;&lt;P&gt;What are the HF's outputs.conf settings?&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jul 2022 16:49:04 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-07-25T16:49:04Z</dc:date>
    <item>
      <title>Splunk Forwarder: Why does it stop sending data after Too Many Fields?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606907#M105409</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have a heavy forwarder that occasionally receives and event that exceeds the bounds of Splunk indexers. When this happens, the heavy forwarder freezes and stops sending data to the indexers. Is there a setting to tell the heavy forwarder to discard that from the queue and keep going? Our only workaround at this time is to restart the heavy forwarder.&amp;nbsp; Thank you.&lt;/P&gt;
&lt;P&gt;This is our limits.conf:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="python"&gt;[kv]
limit = 150
indexed_kv_limit = 0​&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 17:07:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606907#M105409</guid>
      <dc:creator>ohbuckeyeio</dc:creator>
      <dc:date>2022-07-25T17:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder: Stops sending data after Too Many Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606917#M105410</link>
      <description>&lt;P&gt;What is telling you why the forwarder stops sending data?&amp;nbsp; What error message(s) do you get?&lt;/P&gt;&lt;P&gt;What are the HF's outputs.conf settings?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 16:49:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606917#M105410</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-07-25T16:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder: Stops sending data after Too Many Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606925#M105412</link>
      <description>&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Hello Rich,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;Thank you &lt;/SPAN&gt;&lt;SPAN&gt;for&lt;/SPAN&gt;&lt;SPAN&gt; your reply.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;This is the Too Many Fields&amp;nbsp; message that begins our issue:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;&amp;nbsp;07-18-2022 07:19:48.370 &lt;/SPAN&gt;&lt;SPAN&gt;-0700&lt;/SPAN&gt;&lt;SPAN&gt; ERROR TcpInputProc [2721 FwdDataReceiverThread] - Encountered Streaming S2S error=Too many fields (274382) &lt;/SPAN&gt;&lt;SPAN&gt;for&lt;/SPAN&gt;&lt;SPAN&gt; data received from src=myhf.myco.com:62421.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;This is when the queue to the indexer shows as paused:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;&amp;nbsp;07-18-2022 07:48:56.793 &lt;/SPAN&gt;&lt;SPAN&gt;-0700&lt;/SPAN&gt;&lt;SPAN&gt; WARN TcpOutputProc [376 indexerPipe] - The TCP output processor has paused the data flow. Forwarding to host_dest=myindexer.myco.com inside output group my_indexers from host_src=myhf has been blocked &lt;/SPAN&gt;&lt;SPAN&gt;for&lt;/SPAN&gt;&lt;SPAN&gt; blocked_seconds=1740. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health &lt;/SPAN&gt;&lt;SPAN&gt;in&lt;/SPAN&gt;&lt;SPAN&gt; the Splunk Monitoring Console. It is probably not accepting data.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;Here are the results of running btool on this particular machine:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;&lt;BR /&gt;C:\Program Files\Splunk\bin&amp;gt;splunk.exe btool outputs list --debug&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\apps\MY_outputs\default\outputs.conf [indexAndForward]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\apps\MY_outputs\default\outputs.conf index = false&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf [syslog]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf maxEventSize = &lt;/SPAN&gt;&lt;SPAN&gt;1024&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf priority = &amp;lt;13&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf &lt;/SPAN&gt;&lt;SPAN&gt;type&lt;/SPAN&gt;&lt;SPAN&gt; = udp&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\apps\MY_outputs\default\outputs.conf [tcpout]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf ackTimeoutOnShutdown = &lt;/SPAN&gt;&lt;SPAN&gt;30&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf autoLBFrequency = &lt;/SPAN&gt;&lt;SPAN&gt;30&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf autoLBVolume = &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf blockOnCloning = true&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf blockWarnThreshold = &lt;/SPAN&gt;&lt;SPAN&gt;100&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf cipherSuite = &amp;lt;removed by poster&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf compressed = false&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf connectionTTL = &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf connectionTimeout = &lt;/SPAN&gt;&lt;SPAN&gt;20&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\apps\MY_outputs\default\outputs.conf defaultGroup = my_indexers&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf disabled = false&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf dropClonedEventsOnQueueFull = &lt;/SPAN&gt;&lt;SPAN&gt;5&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf dropEventsOnQueueFull = &lt;/SPAN&gt;&lt;SPAN&gt;-1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf ecdhCurves =&amp;lt;removed by poster&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf forceTimebasedAutoLB = false&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf forwardedindex.0.whitelist = .*&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf forwardedindex.1.blacklist = _.*&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf forwardedindex.2.whitelist = (_audit|_internal|_introspection|_telemetry|_metrics|_metrics_rollup)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\apps\MY_outputs\default\outputs.conf forwardedindex.filter.disable = true&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf heartbeatFrequency = &lt;/SPAN&gt;&lt;SPAN&gt;30&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\apps\MY_outputs\default\outputs.conf indexAndForward = false&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf maxConnectionsPerIndexer = &lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf maxFailuresPerInterval = &lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf maxQueueSize = auto&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf readTimeout = &lt;/SPAN&gt;&lt;SPAN&gt;300&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf secsInFailureInterval = &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf sendCookedData = true&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf sslQuietShutdown = false&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf sslVersions = tls1.2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf tcpSendBufSz = &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf useACK = false&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf useClientSSLCompression = true&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\system\default\outputs.conf writeTimeout = &lt;/SPAN&gt;&lt;SPAN&gt;300&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\apps\MY_outputs\default\outputs.conf [tcpout:my_indexers]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;C:\Program Files\Splunk\etc\apps\MY_outputs\default\outputs.conf server = myindexer.myco.com:9997&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 25 Jul 2022 17:27:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606925#M105412</guid>
      <dc:creator>ohbuckeyeio</dc:creator>
      <dc:date>2022-07-25T17:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder: Stops sending data after Too Many Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606929#M105413</link>
      <description>&lt;P&gt;A bug like this was fixed in an 8.2 maintenance release.&amp;nbsp; What version of Splunk is the HF?&amp;nbsp; if it's relatively new then consider opening a Support case on this.&lt;/P&gt;&lt;P&gt;Do you know the data source that is causing this error?&amp;nbsp; If so, have you checked the props.conf settings for it?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 17:49:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606929#M105413</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-07-25T17:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder: Stops sending data after Too Many Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606932#M105415</link>
      <description>&lt;P&gt;That is an interesting development. Do you happen to know the maintenance release or Issue Number where it was fixed? We are running 8.2.6&lt;/P&gt;&lt;P&gt;This is using the Splunk _json sourcetype which has INDEXED_EXTRACTIONS=true. We are going to make our own sourcetype with INDEXED_EXTRACTIONS=false as a workaround.&lt;/P&gt;&lt;P&gt;Either way, it seems there should be a way to prevent the queue from blocking even when INDEXED_EXTRACTIONS=true and the indexer field limit is hit.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 18:10:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606932#M105415</guid>
      <dc:creator>ohbuckeyeio</dc:creator>
      <dc:date>2022-07-25T18:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder: Stops sending data after Too Many Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606942#M105416</link>
      <description>&lt;P&gt;It was a Splunk Cloud version so perhaps the fix did not make it to an on-prem release.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Turning off &lt;FONT face="courier new,courier"&gt;INDEXED_EXTRACTIONS = json&lt;/FONT&gt; is a good workaround and may even improve HF performance.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 19:49:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606942#M105416</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-07-25T19:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder: Stops sending data after Too Many Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606944#M105417</link>
      <description>&lt;P&gt;Thank you for the information, Rich.&amp;nbsp; I will reach out to Support.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 19:54:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/606944#M105417</guid>
      <dc:creator>ohbuckeyeio</dc:creator>
      <dc:date>2022-07-25T19:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder: Stops sending data after Too Many Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/674414#M112878</link>
      <description>&lt;P&gt;Here is the answer on why it's happening.&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Enterprise/Encountered-Streaming-S2S-error-Too-many-fields/m-p/674160" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Enterprise/Encountered-Streaming-S2S-error-Too-many-fields/m-p/674160&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 17:28:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Why-does-it-stop-sending-data-after-Too-Many/m-p/674414#M112878</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2024-01-16T17:28:23Z</dc:date>
    </item>
  </channel>
</rss>

