<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to send the logs from Universal forwaders to Heavy forwaders ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671149#M112510</link>
    <description>&lt;LI-CODE lang="markup"&gt;From UF installed:-
[splunktcp]
_rcvbuf = 1572864
acceptFrom = *
connection_host = ip
evt_dc_name =
evt_dns_name =
evt_resolve_ad_obj = 0
host = prdpl2bcl1101
index = default
logRetireOldS2S = true
logRetireOldS2SMaxCache = 10000
logRetireOldS2SRepeatFrequency = 1d
route = has_key:tautology:parsingQueue;absent_key:tautology:parsingQueue

Splunkcloud inputs machine:
[root@servername bin]# ./splunk btool inputs list splunktcp
[splunktcp]
_rcvbuf = 1572864
acceptFrom = *
connection_host = ip
host = servername.aligntech.com
index = default
logRetireOldS2S = true
logRetireOldS2SMaxCache = 10000
logRetireOldS2SRepeatFrequency = 1d
route = has_key:_replicationBucketUUID:replicationQueue;has_key:_dstrx:typingQueue;has_key:_linebreaker:rulesetQueue;absent_key:_linebreaker:parsingQueue
[splunktcp://9997]
_rcvbuf = 1572864
connection_host = ip
host = servername.aligntech.com
index = default&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 07 Dec 2023 12:12:09 GMT</pubDate>
    <dc:creator>nkamma</dc:creator>
    <dc:date>2023-12-07T12:12:09Z</dc:date>
    <item>
      <title>How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/670980#M112486</link>
      <description>&lt;P&gt;I am trying to send the data from client machine (UF) installed and Heavy forwarder installed on other machine. But i am getting the below error.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;12-06-2023 10:01:22.626 +0100 INFO&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;ClientSessionsManager [3779231 TcpChannelThread] - Adding client: ip=10.112.73.20 uts=windows-x64 id=86E862DA-2CDC-4B21-9E37-45DFF4C5EFBE name=86E862DA-2CDC-4B21-9E37-45DFF4C5EFBE&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;12-06-2023 10:01:22.626 +0100 INFO&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;ClientSessionsManager [3779231 TcpChannelThread] - ip=10.112.73.20 name=86E862DA-2CDC-4B21-9E37-45DFF4C5EFBE New record for &lt;STRONG&gt;sc=100_IngestAction_AutoGenerated app=splunk_ingest_actions: action=Phonehome result=Ok checksum=0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;12-06-2023 10:01:24.551 +0100 INFO&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;AutoLoadBalancedConnectionStrategy [3778953 TcpOutEloop] - Removing quarantine from idx=3.234.1.140:9997 connid=0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;12-06-2023 10:01:24.551 +0100 INFO&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;AutoLoadBalancedConnectionStrategy [3778953 TcpOutEloop] - Removing quarantine from idx=54.85.90.105:9997 connid=0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;12-06-2023 10:01:24.784 +0100 ERROR TcpOutputFd [3778953 TcpOutEloop] - Read error. Connection reset by peer&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;12-06-2023 10:01:25.028 +0100 ERROR TcpOutputFd [3778953 TcpOutEloop] - Read error. Connection reset by peer&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;12-06-2023 10:01:28.082 +0100 WARN&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;TcpOutputProc [3779070 indexerPipe_1] - The TCP output processor has paused the data flow. Forwarding to host_dest=inputs10.align.splunkcloud.com inside output group default-autolb-group from host_src=prdpl2splunk02.aligntech.com has been blocked for blocked_seconds=60. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 09:36:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/670980#M112486</guid>
      <dc:creator>nagesh</dc:creator>
      <dc:date>2023-12-06T09:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/670990#M112488</link>
      <description>&lt;P&gt;OK.&lt;/P&gt;&lt;P&gt;1. What is your setup? You seem to be trying to send the data to Cloud, right?&lt;/P&gt;&lt;P&gt;2. This is a log from where? UF or HF? Because it's trying to send to cloud directly. So if it's the UF's log, your output is not properly configured. If it's a HF's log, then you don't have your network port open on the firewall.&lt;/P&gt;&lt;P&gt;3. What's the whole point of pushing the data from UF via HF? Remember than UF sends data cooked but HF sends the data parsed which means roughly 6x the bandwidth (and you don't get to parse the data on the indexers so some parts of your configuration might not work the way you expect).&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 10:03:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/670990#M112488</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-06T10:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/670991#M112489</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224854"&gt;@nagesh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it seems that there's a block in connections between UF and HF.&lt;/P&gt;&lt;P&gt;At first:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;did you enabled receiving on HF?&lt;/LI&gt;&lt;LI&gt;did you enabled forwardring to the HF on the UF?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Then, check the connection using telnet on the port you're using (default 9997).&lt;/P&gt;&lt;P&gt;If it's all ok, yiou should have, in your Splunk (not on the HF), the Splunk internal logs from that UF:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=&amp;lt;your_UF_hostname&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 10:04:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/670991#M112489</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-12-06T10:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/670995#M112490</link>
      <description>&lt;P&gt;yes , we have the connectivity.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;splunk.exe cmd btool outputs list&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;UF node:&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;[tcpout-server://UFnode:9997]&lt;BR /&gt;[tcpout:default-autolb-group]&lt;BR /&gt;server =UFnode:9997&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;HF:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nagesh_0-1701857886624.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28394iE1B06DA658991360/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nagesh_0-1701857886624.png" alt="nagesh_0-1701857886624.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Not getting the logs in splunk while using the index="_internal" host=""&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 10:18:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/670995#M112490</guid>
      <dc:creator>nagesh</dc:creator>
      <dc:date>2023-12-06T10:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/670998#M112492</link>
      <description>&lt;P&gt;Yes, I am trying to send the data to splunk cloud.&lt;/P&gt;&lt;P&gt;The log file i am trying to receive from UF.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[root@HFNode bin]# telnet inputs2.align.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.com 9997&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Trying 54.159.30.2...&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Connected to inputs2.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Escape character is '^]'.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;^C^C^CConnection closed by foreign host.&lt;BR /&gt;Connected successfully.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 10:35:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/670998#M112492</guid>
      <dc:creator>nagesh</dc:creator>
      <dc:date>2023-12-06T10:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/670999#M112493</link>
      <description>&lt;P&gt;OK. So you have your UF pointed at the Cloud inputs, not at your HF. You should set your output to your HF.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 11:05:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/670999#M112493</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-06T11:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671008#M112494</link>
      <description>&lt;P&gt;Yes, I have created output.conf file and added the required info.&lt;BR /&gt;&lt;BR /&gt;It is placed under&amp;nbsp;&lt;SPAN class=""&gt;etc/system/local/ folder.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;tcpout]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;defaultGroup = default-autolb-group&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;indexAndForward = 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;negotiateProtocolLevel = 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;sslCommonNameToCheck = *.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;sslVerifyServerCert = true&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;useClientSSLCompression = true&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[tcpout-server://inputs1.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com:9997]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[tcpout-server://inputs2.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com:9997]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[tcpout-server://inputs14.align.splunkcloud.com:9997]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[tcpout:default-autolb-group]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;disabled = false&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;server = 54.85.90.105:9997, inputs2.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com:9997, inputs3.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com:9997, .....&lt;BR /&gt;inputs15.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com:9997&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[tcpout-server://inputs15.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com:9997]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;sslCommonNameToCheck = *.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;sslVerifyServerCert = false&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;sslVerifyServerName = false&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;useClientSSLCompression = true&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;autoLBFrequency = 120&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[tcpout:scs]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;disabled=1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;server = stack.forwarders.scs.splunk.com:9997&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;compressed = true&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 12:22:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671008#M112494</guid>
      <dc:creator>nagesh</dc:creator>
      <dc:date>2023-12-06T12:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671013#M112495</link>
      <description>&lt;P&gt;Yes, I have already created output.conf file and added the required info.&lt;/P&gt;
&lt;P&gt;It is placed under the etc/system/local/ folder.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[tcpout]

defaultGroup = default-autolb-group

indexAndForward = 0

negotiateProtocolLevel = 0

sslCommonNameToCheck = *.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com

sslVerifyServerCert = true

useClientSSLCompression = true

[tcpout-server://inputs1.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com:9997]

[tcpout-server://inputs2.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com:9997]

[tcpout-server://inputs14.align.splunkcloud.com:9997]


[tcpout:default-autolb-group]

disabled = false

server = 54.85.90.105:9997, inputs2.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com:9997, inputs3.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com:9997, .....
inputs15.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com:9997

[tcpout-server://inputs15.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com:9997]

sslCommonNameToCheck = *.&amp;lt;&amp;lt;stack&amp;gt;&amp;gt;.splunkcloud.com

sslVerifyServerCert = false

sslVerifyServerName = false

useClientSSLCompression = true

autoLBFrequency = 120

[tcpout:scs]

disabled=1

server = stack.forwarders.scs.splunk.com:9997

compressed = true&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 06 Dec 2023 14:56:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671013#M112495</guid>
      <dc:creator>nagesh</dc:creator>
      <dc:date>2023-12-06T14:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671104#M112501</link>
      <description>&lt;P&gt;Can you provide me ant suggestions to resolve this issue?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 05:39:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671104#M112501</guid>
      <dc:creator>nkamma</dc:creator>
      <dc:date>2023-12-07T05:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671113#M112504</link>
      <description>&lt;P&gt;OK. Because you're posting those config snippets a bit chaotically.&lt;/P&gt;&lt;P&gt;Please do a&lt;/P&gt;&lt;PRE&gt;splunk btool inputs list splunktcp&lt;/PRE&gt;&lt;P&gt;and&lt;/P&gt;&lt;PRE&gt;splunk btool outputs list splunktcp&lt;/PRE&gt;&lt;P&gt;On both of your components.&lt;/P&gt;&lt;P&gt;And while posting the results here please use either code block (the &amp;lt;/&amp;gt; sign on top of the editing window here on the Answers forum) or the "preformatted" paragraph style. Makes it way easier to read.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 07:36:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671113#M112504</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-07T07:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671149#M112510</link>
      <description>&lt;LI-CODE lang="markup"&gt;From UF installed:-
[splunktcp]
_rcvbuf = 1572864
acceptFrom = *
connection_host = ip
evt_dc_name =
evt_dns_name =
evt_resolve_ad_obj = 0
host = prdpl2bcl1101
index = default
logRetireOldS2S = true
logRetireOldS2SMaxCache = 10000
logRetireOldS2SRepeatFrequency = 1d
route = has_key:tautology:parsingQueue;absent_key:tautology:parsingQueue

Splunkcloud inputs machine:
[root@servername bin]# ./splunk btool inputs list splunktcp
[splunktcp]
_rcvbuf = 1572864
acceptFrom = *
connection_host = ip
host = servername.aligntech.com
index = default
logRetireOldS2S = true
logRetireOldS2SMaxCache = 10000
logRetireOldS2SRepeatFrequency = 1d
route = has_key:_replicationBucketUUID:replicationQueue;has_key:_dstrx:typingQueue;has_key:_linebreaker:rulesetQueue;absent_key:_linebreaker:parsingQueue
[splunktcp://9997]
_rcvbuf = 1572864
connection_host = ip
host = servername.aligntech.com
index = default&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 07 Dec 2023 12:12:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671149#M112510</guid>
      <dc:creator>nkamma</dc:creator>
      <dc:date>2023-12-07T12:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671177#M112515</link>
      <description>&lt;P&gt;OK. So these are your inputs.&lt;/P&gt;&lt;P&gt;And your outputs?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 18:03:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671177#M112515</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-07T18:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671230#M112517</link>
      <description>&lt;LI-CODE lang="markup"&gt;Please below.
[root@prdpl2splunk02 bin]# ./splunk btool outputs list 
[rfs]
batchSizeThresholdKB = 131072
batchTimeout = 30
compression = zstd
compressionLevel = 3
dropEventsOnUploadError = false
format = json
format.json.index_time_fields = true
format.ndjson.index_time_fields = true
partitionBy = legacy
[syslog]
maxEventSize = 1024
priority = &amp;lt;13&amp;gt;
type = udp
[tcpout]
ackTimeoutOnShutdown = 30
autoLBFrequency = 30
autoLBVolume = 0
blockOnCloning = true
blockWarnThreshold = 100
cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256:AES128-SHA256:ECDH-ECDSA-AES256-GCM-SHA384:ECDH-ECDSA-AES128-GCM-SHA256:ECDH-ECDSA-AES256-SHA384:ECDH-ECDSA-AES128-SHA256
compressed = false
connectionTTL = 0
connectionTimeout = 20
defaultGroup = default-autolb-group
disabled = false
dropClonedEventsOnQueueFull = 5
dropEventsOnQueueFull = -1
ecdhCurves = prime256v1, secp384r1, secp521r1
enableOldS2SProtocol = false
forceTimebasedAutoLB = false
forwardedindex.0.whitelist = .*
forwardedindex.1.blacklist = _.*
forwardedindex.2.whitelist = (_audit|_introspection|_telemetry)
forwardedindex.filter.disable = false
heartbeatFrequency = 30
indexAndForward = 0
maxConnectionsPerIndexer = 2
maxFailuresPerInterval = 2
maxQueueSize = 500KB
negotiateProtocolLevel = 0
readTimeout = 300
secsInFailureInterval = 1
sendCookedData = true
sslCommonNameToCheck = *.align.splunkcloud.com
sslQuietShutdown = false
sslVerifyServerCert = true
sslVersions = tls1.2
tcpSendBufSz = 0
useACK = false
useClientSSLCompression = true
writeTimeout = 300
[tcpout-server://inputs1.stack.splunkcloud.com:9997]

[tcpout-server://inputs15.stack.splunkcloud.com:9997]
autoLBFrequency = 120
sslCommonNameToCheck = *.stack.splunkcloud.com
sslVerifyServerCert = false
sslVerifyServerName = false
useClientSSLCompression = true
[tcpout-server://inputs2.stack.splunkcloud.com:9997]
[tcpout-server://inputs3.stack.splunkcloud.com:9997]
[tcpout-server://inputs4.stack.splunkcloud.com:9997]
[tcpout-server://inputs5.stack.splunkcloud.com:9997]
[tcpout-server://inputs6.stack.splunkcloud.com:9997]
[tcpout-server://inputs7.stack.splunkcloud.com:9997]
[tcpout-server://inputs8.stack.splunkcloud.com:9997]
[tcpout-server://inputs9.stack.splunkcloud.com:9997]
[tcpout:default-autolb-group]
disabled = false
server = 54.85.90.105:9997, inputs2.stack.splunkcloud.com:9997, inputs3.stack.splunkcloud.com:9997,...... inputs15.stack.splunkcloud.com:9997
[tcpout:scs]
compressed = true
disabled = 1
server = stack.forwarders.scs.splunk.com:9997
UF Output:
[rfs]
batchSizeThresholdKB = 131072
batchTimeout = 30
compression = zstd
compressionLevel = 3
dropEventsOnUploadError = false
format = json
format.json.index_time_fields = true
format.ndjson.index_time_fields = true
partitionBy = legacy
[syslog]
maxEventSize = 1024
priority = &amp;lt;13&amp;gt;
type = udp
[tcpout]
ackTimeoutOnShutdown = 30
autoLBFrequency = 30
autoLBVolume = 0
blockOnCloning = true
blockWarnThreshold = 100
cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256:AES128-SHA256:ECDH-ECDSA-AES256-GCM-SHA384:ECDH-ECDSA-AES128-GCM-SHA256:ECDH-ECDSA-AES256-SHA384:ECDH-ECDSA-AES128-SHA256
compressed = false
connectionTTL = 0
connectionTimeout = 20
defaultGroup = default-autolb-group
disabled = false
dropClonedEventsOnQueueFull = 5
dropEventsOnQueueFull = -1
ecdhCurves = prime256v1, secp384r1, secp521r1
enableOldS2SProtocol = false
forceTimebasedAutoLB = false
forwardedindex.0.whitelist = .*
forwardedindex.1.blacklist = _.*
forwardedindex.2.whitelist = (_audit|_introspection|_internal|_telemetry|_configtracker)
forwardedindex.filter.disable = false
heartbeatFrequency = 30
indexAndForward = false
maxConnectionsPerIndexer = 2
maxFailuresPerInterval = 2
maxQueueSize = auto
readTimeout = 300
secsInFailureInterval = 1
sendCookedData = true
sslQuietShutdown = false
sslVersions = tls1.2
tcpSendBufSz = 0
useACK = false
useClientSSLCompression = true
writeTimeout = 300
[tcpout-server://prdpl2splunk02.domainame.com:9997]
[tcpout:default-autolb-group]
server = prdpl2splunk02.domainame.com:9997&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 08 Dec 2023 08:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671230#M112517</guid>
      <dc:creator>nkamma</dc:creator>
      <dc:date>2023-12-08T08:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671396#M112527</link>
      <description>&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 03:28:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671396#M112527</guid>
      <dc:creator>nagesh</dc:creator>
      <dc:date>2023-12-11T03:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671405#M112531</link>
      <description>&lt;P&gt;Sending logs from Universal Forwarders to Heavy Forwarders is like passing along important messages from one person to another in a relay. Here's a simple way to understand it:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Imagine Passing Notes:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Think of Universal Forwarders as individuals who have notes (logs) with important information. Heavy Forwarders are the ones ready to collect and manage these notes.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Universal Forwarders (Note Holders):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Universal Forwarders are like people holding notes (logs) and standing in a line. They generate logs from different sources on a computer.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Heavy Forwarders (Note Collectors):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Heavy Forwarders are the ones waiting at the end of the line to collect these notes (logs) from the Universal Forwarders.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Setting Up the Relay:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You set up a system where each person (Universal Forwarder) in the line passes their note (log) to the next person (Heavy Forwarder) until it reaches the end.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Configuring Universal Forwarders:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;On each computer with a Universal Forwarder, you configure it to know where the next person (Heavy Forwarder) is in line. This is like telling each note holder where to pass their note.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Logs Move Down the Line:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;As logs are generated, they move down the line from Universal Forwarder to Universal Forwarder until they reach the Heavy Forwarder.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Heavy Forwarder Collects and Manages:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The Heavy Forwarder collects all the notes (logs) from different Universal Forwarders. It's like the person at the end of the line collecting all the notes to manage and make sense of them.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Centralized Log Management:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Now, all the important information is centralized on the Heavy Forwarder, making it easier to analyze and keep track of everything in one place.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;In technical terms, configuring Universal Forwarders to send logs to Heavy Forwarders involves setting up these systems to efficiently collect and manage logs from different sources across a network. It's like orchestrating a relay of information to ensure that important data reaches its destination for centralized management and analysis.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 06:16:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671405#M112531</guid>
      <dc:creator>soniya-01</dc:creator>
      <dc:date>2023-12-11T06:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to send the logs from Universal forwaders to Heavy forwaders ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671472#M112543</link>
      <description>&lt;P&gt;At first glance it looks relatively OK. You have your inputs matching your outputs.&lt;/P&gt;&lt;P&gt;Check your splunkd.log on the sending UF and the receiving HF. There should be hints as to the reason for lack of connectivity. If nothing else helps - try to tcpdump the traffic and see what's going on there.&lt;/P&gt;&lt;P&gt;EDIT: OK, your initial post says that you get "Connection reset by peer" but it's a bit unclear which side this is from.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 20:32:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-logs-from-Universal-forwaders-to-Heavy-forwaders/m-p/671472#M112543</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-11T20:32:49Z</dc:date>
    </item>
  </channel>
</rss>

