<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to troubleshoot error on Splunk 6 universal forwarder &amp;quot;TcpOutputProc - Forwarding to indexer group GSOC blocked for 9500 seconds.&amp;quot;? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-error-on-Splunk-6-universal-forwarder-quot/m-p/125088#M25802</link>
    <description>&lt;P&gt;how to fix this error , "WARN  TcpOutputProc - Forwarding to indexer group GSOC blocked for 9500 seconds". I cant receive security logs or any logs from my DC Servers, I am using SUF version 6 on a deployment Server &lt;/P&gt;</description>
    <pubDate>Fri, 21 Nov 2014 08:35:06 GMT</pubDate>
    <dc:creator>tiny3001</dc:creator>
    <dc:date>2014-11-21T08:35:06Z</dc:date>
    <item>
      <title>How to troubleshoot error on Splunk 6 universal forwarder "TcpOutputProc - Forwarding to indexer group GSOC blocked for 9500 seconds."?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-error-on-Splunk-6-universal-forwarder-quot/m-p/125088#M25802</link>
      <description>&lt;P&gt;how to fix this error , "WARN  TcpOutputProc - Forwarding to indexer group GSOC blocked for 9500 seconds". I cant receive security logs or any logs from my DC Servers, I am using SUF version 6 on a deployment Server &lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 08:35:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-error-on-Splunk-6-universal-forwarder-quot/m-p/125088#M25802</guid>
      <dc:creator>tiny3001</dc:creator>
      <dc:date>2014-11-21T08:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot error on Splunk 6 universal forwarder "TcpOutputProc - Forwarding to indexer group GSOC blocked for 9500 seconds."?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-error-on-Splunk-6-universal-forwarder-quot/m-p/125089#M25803</link>
      <description>&lt;P&gt;Hi tiny3001,&lt;/P&gt;

&lt;P&gt;start troubleshooting why the queues are blocked. See the wiki &lt;A href="http://wiki.splunk.com/Community:TroubleshootingBlockedQueues"&gt;http://wiki.splunk.com/Community:TroubleshootingBlockedQueues&lt;/A&gt; or use the S.o.S. App &lt;A href="https://apps.splunk.com/app/748/"&gt;https://apps.splunk.com/app/748/&lt;/A&gt; on the indexer. As well start to setup persistent queues on the UF &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Usepersistentqueues"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Usepersistentqueues&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 08:48:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-error-on-Splunk-6-universal-forwarder-quot/m-p/125089#M25803</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-11-21T08:48:19Z</dc:date>
    </item>
  </channel>
</rss>

