<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder to Splunk cloud suddenly stop: error tcpoutputfd 1158951 connection to host 9997 failed ssl error = no err in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-to-Splunk-cloud-suddenly-stop-error-tcpoutputfd/m-p/756235#M119952</link>
    <description>&lt;P&gt;As far as I remember, error 104 means problems on a tcp connection level. Troubleshoot the connection with your typical network-level tools (tcpdump, netcat...) and verify your firewall config/logs.&lt;/P&gt;</description>
    <pubDate>Sat, 06 Dec 2025 06:57:40 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2025-12-06T06:57:40Z</dc:date>
    <item>
      <title>Forwarder to Splunk cloud suddenly stop: error tcpoutputfd 1158951 connection to host 9997 failed ssl error = no error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-to-Splunk-cloud-suddenly-stop-error-tcpoutputfd/m-p/756233#M119950</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I have&amp;nbsp; HF and UF act as intermediate forwarders and forward logs to Splunk Cloud. We installed the credentials (.spl file) download from Splunk Cloud, and the forwarders were working fine until November 28, they have stopped sending the log to Splunk cloud. &lt;STRONG&gt;The error in splunkd.log is:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ThuLe_0-1764992510512.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/40980iFACD225381830420/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ThuLe_0-1764992510512.png" alt="ThuLe_0-1764992510512.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Network team confirm that they not change anything on the FW&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have searched and &lt;STRONG&gt;tried re-downloading the credentials (.spl file) from Splunk Cloud and reinstalled them on the forwarders, but the same errors persist. The errors only disappear when we disable the credentials app 100_&amp;lt;cloud instance&amp;gt;_splunkcloud&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;Has anyone experienced this issue? Please help&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you very much&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Dec 2025 03:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-to-Splunk-cloud-suddenly-stop-error-tcpoutputfd/m-p/756233#M119950</guid>
      <dc:creator>ThuLe</dc:creator>
      <dc:date>2025-12-06T03:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder to Splunk cloud suddenly stop: error tcpoutputfd 1158951 connection to host 9997 failed ssl error = no err</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-to-Splunk-cloud-suddenly-stop-error-tcpoutputfd/m-p/756235#M119952</link>
      <description>&lt;P&gt;As far as I remember, error 104 means problems on a tcp connection level. Troubleshoot the connection with your typical network-level tools (tcpdump, netcat...) and verify your firewall config/logs.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Dec 2025 06:57:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-to-Splunk-cloud-suddenly-stop-error-tcpoutputfd/m-p/756235#M119952</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-12-06T06:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder to Splunk cloud suddenly stop: error tcpoutputfd 1158951 connection to host 9997 failed ssl error = no err</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-to-Splunk-cloud-suddenly-stop-error-tcpoutputfd/m-p/756257#M119953</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260285"&gt;@ThuLe&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my experience with 104 socket error (ECONNRESET) it has been a firewall issue every time, even when I was told there was no firewall between the two points (spoiler - there was!)&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found that where a firewall was either blocking the content or attempting SSL introspection then it can cause the 104 error (which is&amp;nbsp;&lt;EM&gt;ECONNRESET)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Sun, 07 Dec 2025 22:12:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-to-Splunk-cloud-suddenly-stop-error-tcpoutputfd/m-p/756257#M119953</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-12-07T22:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder to Splunk cloud suddenly stop: error tcpoutputfd 1158951 connection to host 9997 failed ssl error = no err</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-to-Splunk-cloud-suddenly-stop-error-tcpoutputfd/m-p/756259#M119954</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260285"&gt;@ThuLe&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most probably network related.&lt;BR /&gt;-Check connectivity to Splunk Cloud -&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;telnet inputs1.STACKID.splunkcloud.com 9997&lt;/LI-CODE&gt;&lt;P&gt;-Check Firewall/SSL inspection recently enabled or changed&lt;/P&gt;&lt;P&gt;#&lt;A href="https://splunk.my.site.com/customer/s/article/Splunk-Universal-Forwarder-is-not-sending-events-to-Splunk-Cloud" target="_blank"&gt;https://splunk.my.site.com/customer/s/article/Splunk-Universal-Forwarder-is-not-sending-events-to-Splunk-Cloud&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2025 03:40:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-to-Splunk-cloud-suddenly-stop-error-tcpoutputfd/m-p/756259#M119954</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-12-08T03:40:05Z</dc:date>
    </item>
  </channel>
</rss>

