<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SplunkCloud - Heavy Forwarder Communication in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654313#M110920</link>
    <description>&lt;P&gt;Hi.&amp;nbsp; Isn't this saying&amp;nbsp; indexer&amp;nbsp;&lt;SPAN&gt;inputs1.XXXX.splunkcloud.com has full queues?&lt;BR /&gt;&lt;BR /&gt;Can you look at the queues there? Messages?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Aug 2023 21:08:42 GMT</pubDate>
    <dc:creator>burwell</dc:creator>
    <dc:date>2023-08-14T21:08:42Z</dc:date>
    <item>
      <title>SplunkCloud - Heavy Forwarder Communication: Why is my heavy forwarder is now skipping data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654312#M110919</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Hi friends.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;I've followed de path to use UniversarForwarder app from my splunk cloud enviromen. But i have the next message:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;The TCP output processor has paused the data flow. Forwarding to host_dest=inputs1.XXXX.splunkcloud.com inside output group splunkcloud_ from host_src=YYYYYY has been blocked for blocked_seconds=10. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data. Learn more.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;I've tested the communications to splunk cloud &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;splunkcloud.com:9997&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;splunkcloud.com:8000&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;splunkcloud.com:8089&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;And all are OK.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;My heavy forwarder is now skipping data. Is there something else I clould check out?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 19:45:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654312#M110919</guid>
      <dc:creator>herguzav</dc:creator>
      <dc:date>2023-08-15T19:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud - Heavy Forwarder Communication</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654313#M110920</link>
      <description>&lt;P&gt;Hi.&amp;nbsp; Isn't this saying&amp;nbsp; indexer&amp;nbsp;&lt;SPAN&gt;inputs1.XXXX.splunkcloud.com has full queues?&lt;BR /&gt;&lt;BR /&gt;Can you look at the queues there? Messages?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 21:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654313#M110920</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2023-08-14T21:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud - Heavy Forwarder Communication</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654315#M110921</link>
      <description>&lt;P&gt;Hi!!&lt;BR /&gt;&lt;BR /&gt;All splunkcloud queues are ok. Even my other heavy forwarder is working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have another test to do?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 00:56:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654315#M110921</guid>
      <dc:creator>herguzav</dc:creator>
      <dc:date>2023-08-15T00:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud - Heavy Forwarder Communication</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654344#M110923</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Usually it's like&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/155648"&gt;@burwell&lt;/a&gt;&amp;nbsp;said. This error/warning means that for some reason there are some queues full. Earlier You could try this&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=*.&amp;lt;your stack name&amp;gt;.splunkcloud.com source=*metrics.log sourcetype=splunkd TERM(group=queue) (TERM(name=parsingQueue) OR TERM(name=indexqueue) OR TERM(name=tcpin_queue) OR TERM(name=aggqueue))
| eval is_blocked=if(blocked=="true",1,0), host_queue=host." - ".name
| stats sparkline sum(is_blocked) as blocked,count by host_queue
| eval blocked_ratio=round(blocked/count*100,2)
| where blocked_ratio &amp;gt; 0
| sort 50 -blocked_ratio 
| eval requires_attention=case(blocked_ratio&amp;gt;50.0,"fix highly recommended!",blocked_ratio&amp;gt;40.0,"you better check..",blocked_ratio&amp;gt;20.0,"usually no need to worry but keep an eye on it",1=1,"not unusual")&lt;/LI-CODE&gt;&lt;P&gt;to check &amp;nbsp;what is status of those input forwarders. But not I cannot see that information on SC, probably it's forwarder to somewhere else?&lt;/P&gt;&lt;P&gt;I suppose that you will create a ticket to SC support and ask situation about those input forwarders.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 09:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654344#M110923</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-08-15T09:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud - Heavy Forwarder Communication</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654420#M110936</link>
      <description>&lt;P&gt;Hi&amp;nbsp;.&lt;BR /&gt;&lt;BR /&gt;I've run your search and no results were displayed, I've retired the condition and all results said&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;"not unusual"&lt;/PRE&gt;&lt;P&gt;The problem persist. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 00:17:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654420#M110936</guid>
      <dc:creator>herguzav</dc:creator>
      <dc:date>2023-08-16T00:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkCloud - Heavy Forwarder Communication</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654815#M110988</link>
      <description>&lt;P&gt;As I said, I cannot see that information (inputs1-15) on SC side anymore. Earlier this was stored to customer cloud stack, but now I expecting that this information is currently forwarder to Splunk Clouds' admin stack or somewhere else where Customers haven't access?&lt;/P&gt;&lt;P&gt;I think that you haven't any other option than create a support ticket to Splunk and ask that they solve this issue.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 08:01:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkCloud-Heavy-Forwarder-Communication-Why-is-my-heavy/m-p/654815#M110988</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-08-18T08:01:35Z</dc:date>
    </item>
  </channel>
</rss>

