<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HF can't reach splunk cloud in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HF-can-t-reach-splunk-cloud/m-p/690868#M114931</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/269081"&gt;@wxlcba&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;in addition to the checks hinted by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/79189"&gt;@deepakc&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;did you downloaded and installed on your HFs the forwarder app from SplunkCloud? it contains the configuration for the connection.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jun 2024 08:05:53 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-06-17T08:05:53Z</dc:date>
    <item>
      <title>HF can't reach splunk cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-can-t-reach-splunk-cloud/m-p/690839#M114926</link>
      <description>&lt;P&gt;I've created the HF, and set up the ip allow list. From the Azure&amp;nbsp;Connection troubleshoot, the testing is successful, NSG has createa and allow all connection to internet, then Windows firewall is disabled in the VM.&lt;/P&gt;&lt;P&gt;but I still get this error.&lt;/P&gt;&lt;P&gt;06-16-2024 22:59:24.253 +0000 WARN AutoLoadBalancedConnectionStrategy [8760 TcpOutEloop] - Cooked connection to ip=1.2.3.4:9997 timed out&lt;BR /&gt;06-16-2024 22:59:24.563 +0000 ERROR TcpOutputFd [8760 TcpOutEloop] - Read error. An existing connection was forcibly closed by the remote host.&lt;BR /&gt;06-16-2024 22:59:24.876 +0000 ERROR TcpOutputFd [8760 TcpOutEloop] - Read error. An existing connection was forcibly closed by the remote host.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;running the comand netstat -anob to check the connections it will be stuck in the&amp;nbsp;SYN_SENT status. but the messages said HF&amp;nbsp;&lt;SPAN&gt;has been blocked for blocked_seconds=10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;any ideas for fixing this issues?&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jun 2024 23:45:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-can-t-reach-splunk-cloud/m-p/690839#M114926</guid>
      <dc:creator>wxlcba</dc:creator>
      <dc:date>2024-06-16T23:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: HF can't reach splunk cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-can-t-reach-splunk-cloud/m-p/690866#M114930</link>
      <description>&lt;P&gt;&lt;SPAN&gt;It could be several things blocking you. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;TcpOutputFd (this is normally a networking or config setting)&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You have set the whitelist and disabled the FW. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Other things to check: &lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Check your network allows for the HF to route outbound to Splunk cloud &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Deploy the Splunk Credentials Package to the HF - &lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.2.1/Forwarder/ConfigSCUFCredentials" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Forwarder/9.2.1/Forwarder/ConfigSCUFCredentials&lt;/A&gt; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Check you can connect – try this command:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; openssl s_client -connect inputs1.MY_STACK_NAME&amp;gt;.splunkcloud.com:9997​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Further than that more troubleshooting is required. But it’s usually a networking that’s blocking.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 08:00:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-can-t-reach-splunk-cloud/m-p/690866#M114930</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-06-17T08:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: HF can't reach splunk cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HF-can-t-reach-splunk-cloud/m-p/690868#M114931</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/269081"&gt;@wxlcba&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;in addition to the checks hinted by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/79189"&gt;@deepakc&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;did you downloaded and installed on your HFs the forwarder app from SplunkCloud? it contains the configuration for the connection.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 08:05:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HF-can-t-reach-splunk-cloud/m-p/690868#M114931</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-17T08:05:53Z</dc:date>
    </item>
  </channel>
</rss>

