<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is heavy forwarder repeatedly getting &amp;quot;WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 600 seconds.&amp;quot; in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116914#M24369</link>
    <description>&lt;P&gt;Please post your questions..I am sure you will get answers. &lt;/P&gt;</description>
    <pubDate>Wed, 04 Mar 2015 07:37:56 GMT</pubDate>
    <dc:creator>satishsdange</dc:creator>
    <dc:date>2015-03-04T07:37:56Z</dc:date>
    <item>
      <title>Why is heavy forwarder repeatedly getting "WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 600 seconds."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116910#M24365</link>
      <description>&lt;P&gt;We are seeing the following errors on our Heavy Forwarder side:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;09-05-2014 13:39:06.483 - 0400 INFO TcpOutputProc - Connected to idx= 23.42.214.219:9997
09-05-2014 13:39:06.484 - 0400 WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 600 seconds.
09-05-2014 13:39:36.493 - 0400 INFO TcpOutputProc - Connected to idx= 23.42.214.219:9997
09-05-2014 13:40:06.501 - 0400 INFO TcpOutputProc - Connected to idx= 23.42.214.219:9997
09-05-2014 13:40:36.509 - 0400 INFO TcpOutputProc - Connected to idx= 23.42.214.219:9997
09-05-2014 13:40:39.510 - 0400 WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 700 seconds.
09-05-2014 13:41:06.517 - 0400 INFO TcpOutputProc - Connected to idx= 23.42.214.219:9997
09-05-2014 13:41:36.524 - 0400 INFO TcpOutputProc - Connected to idx= 23.42.214.219:9997
09-05-2014 13:42:06.533 - 0400 INFO TcpOutputProc - Connected to idx= 23.42.214.219:9997
09-05-2014 13:42:19.536 - 0400 WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 800 seconds.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This continues to repeat through the current date. Anyone else experience this or have any suggestions?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2014 11:57:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116910#M24365</guid>
      <dc:creator>hagjos43</dc:creator>
      <dc:date>2014-09-09T11:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why is heavy forwarder repeatedly getting "WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 600 seconds."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116911#M24366</link>
      <description>&lt;P&gt;I don't have the answer, but I've got the same issue!!!!  Anyone????&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2015 17:34:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116911#M24366</guid>
      <dc:creator>cdupuis123</dc:creator>
      <dc:date>2015-01-12T17:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why is heavy forwarder repeatedly getting "WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 600 seconds."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116912#M24367</link>
      <description>&lt;P&gt;Same here,, started happening. Is it due to bad band width or to many seconds between collections? I use the 9*Nix app to collect audit logs using rlog.sh&lt;/P&gt;</description>
      <pubDate>Fri, 20 Feb 2015 21:10:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116912#M24367</guid>
      <dc:creator>djfisher</dc:creator>
      <dc:date>2015-02-20T21:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why is heavy forwarder repeatedly getting "WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 600 seconds."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116913#M24368</link>
      <description>&lt;P&gt;I am currently evaluating Splunk.   Ceaselessly, I encounter errors like this and "answers.splunk.com" has no answers, only other frustrated questioners.&lt;/P&gt;

&lt;P&gt;Why does anyone use this software???&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2015 17:37:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116913#M24368</guid>
      <dc:creator>inters</dc:creator>
      <dc:date>2015-03-03T17:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why is heavy forwarder repeatedly getting "WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 600 seconds."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116914#M24369</link>
      <description>&lt;P&gt;Please post your questions..I am sure you will get answers. &lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2015 07:37:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116914#M24369</guid>
      <dc:creator>satishsdange</dc:creator>
      <dc:date>2015-03-04T07:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why is heavy forwarder repeatedly getting "WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 600 seconds."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116915#M24370</link>
      <description>&lt;P&gt;Hi inters&lt;/P&gt;

&lt;P&gt;Yes I've spent time on the answers site with similar results, but after using/running Splunk now for 3 years I've found that if I can't get the answer from Splunk answers I've either used the wrong search term, or most times I find something close and am able to backwards/sideways engineer it until it fixes my issue.  Oh course if all else fails call my SE or Support.  Good luck with your POC&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2015 10:36:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116915#M24370</guid>
      <dc:creator>cdupuis123</dc:creator>
      <dc:date>2015-03-05T10:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why is heavy forwarder repeatedly getting "WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 600 seconds."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116916#M24371</link>
      <description>&lt;P&gt;See this post for step to troubleshoot: &lt;A href="http://answers.splunk.com/answers/189238/how-to-troubleshoot-error-on-splunk-6-universal-fo.html"&gt;http://answers.splunk.com/answers/189238/how-to-troubleshoot-error-on-splunk-6-universal-fo.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;but in general I'd use Splunk on Splunk (SoS) app to diagnose where the bottleneck is.  If you are running 6.3, you can use the DMC (Distributed Management Console) to do the same analysis:  Goto Setting and click Distribute Management Console icon on the left.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 16:48:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116916#M24371</guid>
      <dc:creator>khourihan_splun</dc:creator>
      <dc:date>2015-09-28T16:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why is heavy forwarder repeatedly getting "WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 600 seconds."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116917#M24372</link>
      <description>&lt;P&gt;Have you a Forwarder Loop?&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/217915/splunk-app-for-windows-infrastructure-forwarding-t.html"&gt;https://answers.splunk.com/answers/217915/splunk-app-for-windows-infrastructure-forwarding-t.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2016 16:36:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116917#M24372</guid>
      <dc:creator>bohanlon_splunk</dc:creator>
      <dc:date>2016-01-29T16:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why is heavy forwarder repeatedly getting "WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 600 seconds."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116918#M24373</link>
      <description>&lt;P&gt;From my experience, this is usually due to blocked queues at the indexers. The most common cause is insufficient IOPS/throughput at the indexers' disk subsystem. When a queue is full for a certain length of time on the indexer, the indexer will start rejecting forwarder connections so that it can clear its full queue(s) before processing new events. &lt;/P&gt;

&lt;P&gt;Here are some searches you can run against the _internal index of your indexers to find and see the bottleneck:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;View the current queue size:&lt;/STRONG&gt; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*metrics.log group=queue | timechart median(current_size) by name
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Find blocked queue events:&lt;/STRONG&gt; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*metrics.log group=queue blocked
Blocked queues in last 24 hours by queue and Splunk server: 
index=_internal source=*metrics.log sourcetype=splunkd group=queue | eval max=if(isnotnull(max_size_kb),max_size_kb,max_size)  | eval curr=if(isnotnull(current_size_kb),current_size_kb,current_size)  | eval fill_perc=round((curr/max)*100,2) | eval name=host.":".name | where fill_perc&amp;gt;=99.0 | timechart max(fill_perc) as MaxFillPerc by name useother=false limit=100 minspan=1h
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Count how many times queues were &amp;gt;=99% by Queue Name and Splunk Server&lt;/STRONG&gt; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*metrics.log sourcetype=splunkd group=queue | eval max=if(isnotnull(max_size_kb),max_size_kb,max_size) | eval curr=if(isnotnull(current_size_kb),current_size_kb,current_size)  | eval fill_perc=round((curr/max)*100,2) | where fill_perc&amp;gt;=99.0 | stats count by name host  | eval name=case(name=="aggqueue","2 - Aggregation Queue",name=="indexqueue","4 - Indexing Queue",name=="parsingqueue","1 - Parsing Queue",name=="typingqueue","3 - Typing Queue", 1=1, name) 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 29 Jan 2016 18:45:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116918#M24373</guid>
      <dc:creator>masonmorales</dc:creator>
      <dc:date>2016-01-29T18:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why is heavy forwarder repeatedly getting "WARN TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 600 seconds."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116919#M24374</link>
      <description>&lt;P&gt;Try checking your metrics.log on both your HF and indexer. &lt;/P&gt;

&lt;P&gt;Do you see any blocked queues (like the parsingqueue or aggqueue or tcpinqueue)?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2016 18:49:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-heavy-forwarder-repeatedly-getting-quot-WARN/m-p/116919#M24374</guid>
      <dc:creator>PGrantham</dc:creator>
      <dc:date>2016-01-29T18:49:14Z</dc:date>
    </item>
  </channel>
</rss>

