<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TcpOutputFd [800 TcpOutEloop] - Connection to host=xx.xxx.xxx.xxx:9997 failed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-logs-stopped-abruptly-after-installing-UF-on-my-windows/m-p/627552#M107722</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248866"&gt;@thevikramyadav&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if your Splunk server continues to receive logs from other Universal Forwarders, the problem could be in the connection.&lt;/P&gt;&lt;P&gt;Check it using telnet:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;telnet &amp;lt;ip_splunk_server&amp;gt; 9997&lt;/LI-CODE&gt;&lt;P&gt;maybe something changed in the firewall rules.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jan 2023 07:32:04 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-01-19T07:32:04Z</dc:date>
    <item>
      <title>Why did logs stopped abruptly after installing UF on my windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-logs-stopped-abruptly-after-installing-UF-on-my-windows/m-p/627529#M107721</link>
      <description>&lt;P&gt;Hi Guys, I have UF installed on my windows machine, &lt;SPAN&gt;abruptly&lt;/SPAN&gt; last month logs got stopped. I check in splunkd log file and saw the error&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;TcpOutputFd [800 TcpOutEloop] - Connection to host=xx.xxx.xxx.xxx:9997 failed&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Also after restarting, it resumes sending logs to Splunk for some days but again it will stop and gives the same error.&lt;BR /&gt;&lt;BR /&gt;Not sure how to fix this issue and proceed.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 18:12:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-logs-stopped-abruptly-after-installing-UF-on-my-windows/m-p/627529#M107721</guid>
      <dc:creator>thevikramyadav</dc:creator>
      <dc:date>2023-01-19T18:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: TcpOutputFd [800 TcpOutEloop] - Connection to host=xx.xxx.xxx.xxx:9997 failed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-logs-stopped-abruptly-after-installing-UF-on-my-windows/m-p/627552#M107722</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248866"&gt;@thevikramyadav&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if your Splunk server continues to receive logs from other Universal Forwarders, the problem could be in the connection.&lt;/P&gt;&lt;P&gt;Check it using telnet:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;telnet &amp;lt;ip_splunk_server&amp;gt; 9997&lt;/LI-CODE&gt;&lt;P&gt;maybe something changed in the firewall rules.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 07:32:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-logs-stopped-abruptly-after-installing-UF-on-my-windows/m-p/627552#M107722</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-19T07:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why did logs stopped abruptly after installing UF on my windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-logs-stopped-abruptly-after-installing-UF-on-my-windows/m-p/753772#M119664</link>
      <description>&lt;P&gt;Any updates on how to fix this issue.&lt;BR /&gt;We are facing a similar issue where hosts randomly stop reporting to the HF. Restarting the Splunk Universal Forwarder service fixes the issue for a while before the issue comes back again and the hosts stop reporting to Splunk HF again.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 08:54:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-logs-stopped-abruptly-after-installing-UF-on-my-windows/m-p/753772#M119664</guid>
      <dc:creator>yazeedallabadi2</dc:creator>
      <dc:date>2025-09-30T08:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why did logs stopped abruptly after installing UF on my windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-logs-stopped-abruptly-after-installing-UF-on-my-windows/m-p/753785#M119666</link>
      <description>&lt;P&gt;And are you sure that it's the Splunk's issue? From the symptoms it could as well be a lot of other issues - OS-level ones, network ones... Have you done _any_ troubleshooting or just assumed that it's Splunk's fault? I'm not saying it isn't but how did you come to that conclusion?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 11:22:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-logs-stopped-abruptly-after-installing-UF-on-my-windows/m-p/753785#M119666</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-09-30T11:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why did logs stopped abruptly after installing UF on my windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-did-logs-stopped-abruptly-after-installing-UF-on-my-windows/m-p/754753#M119789</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313347"&gt;@yazeedallabadi2&lt;/a&gt;&amp;nbsp;did you see this&amp;nbsp;&lt;A href="https://splunk.my.site.com/customer/s/article/HF-paused-data-flow-due-to-connection-timeout-but-didn-t-resume-data-transfer-after-the-connection-is-established" target="_blank"&gt;https://splunk.my.site.com/customer/s/article/HF-paused-data-flow-due-to-connection-timeout-but-didn-t-resume-data-transfer-after-the-connection-is-established&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I see that it says it affects UF as well as HF&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Oct 2025 02:58:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-did-logs-stopped-abruptly-after-installing-UF-on-my-windows/m-p/754753#M119789</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2025-10-26T02:58:01Z</dc:date>
    </item>
  </channel>
</rss>

