<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ERROR TcpInputProc - Indexer not receiving data from forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Indexer-not-receiving-data-from-forwarder/m-p/288011#M55050</link>
    <description>&lt;P&gt;Hi all, I am getting these errors in my log files. First is from the spunkd.log from the indexer and second is is from the splunkd.log on the forwarder. I have done multiple searches on Splunk answers, but I haven't found one that pertain to both. It obvious in the error log on the forwarder that the connection is refused however I can telnet to the port 9997. What am I missing? This was all working until upgrading to 7.02. Thankfully this is just a test machine and not in production. Please let me know what I can provide you all to assist me in troubleshooting such as .conf/log files etc. I will continue to search &amp;amp; troubleshoot, but at this point I am loss.&lt;/P&gt;

&lt;P&gt;Splunk IDX Error:&lt;/P&gt;

&lt;P&gt;ERROR TcpInputProc - Message rejected. Received unexpected message of size=369295616 bytes from src=xxx.xx.xxx.xx:64529 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.&lt;/P&gt;

&lt;P&gt;ERROR TcpInputProc - Message rejected. Received unexpected message of size=369295616 bytes from src=xxx.xx.xxx.xx:61330 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.&lt;/P&gt;

&lt;P&gt;Splunk UF Error:&lt;/P&gt;

&lt;P&gt;WARN  TcpOutputProc - Applying quarantine to ip=xxx.xx.xxx.xx port=9997 _numberOfFailures=2&lt;BR /&gt;
WARN  TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group primary_indexers has been blocked for 3601 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;

&lt;P&gt;INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_xxx.xx.xxx.xx_8089_&lt;EM&gt;XA5D5CF2-F5DB-4F1F-BAE9-909B3A7FEA00&lt;BR /&gt;
INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_xxx.xx.xxx.xx_8089&lt;/EM&gt;_XA5D5CF2-F5DB-4F1F-BAE9-909B3A7FEA00&lt;/P&gt;

&lt;P&gt;WARN  TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group primary_indexers has been blocked for 3701 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;

&lt;P&gt;INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_xxx.xx.xxx.xx_8089_ _XA5D5CF2-F5DB-4F1F-BAE9-909B3A7FEA00&lt;/P&gt;

&lt;P&gt;WARN  TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group primary_indexers has been blocked for 3801 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;

&lt;P&gt;INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_xxx.xx.xxx.xx_8089_&lt;EM&gt;XA5D5CF2-F5DB-4F1F-BAE9-909B3A7FEA00&lt;BR /&gt;
INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_xxx.xx.xxx.xx_8089&lt;/EM&gt;&lt;EM&gt;XA5D5CF2-F5DB-4F1F-BAE9-909B3A7FEA00&lt;BR /&gt;
INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_xxx.xx.xxx.xx_8089&lt;/EM&gt;_XA5D5CF2-F5DB-4F1F-BAE9-909B3A7FEA00&lt;BR /&gt;
WARN  TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group primary_indexers has been blocked for 3901 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;

&lt;P&gt;INFO  TcpOutputProc - Removing quarantine from idx=xxx.xx.xxx.xx:9997&lt;/P&gt;

&lt;P&gt;ERROR TcpOutputFd - Connection to host=xxx.xx.xxx:9997 failed&lt;BR /&gt;
ERROR TcpOutputFd - Connection to host=xxx.xx.xxx:9997 failed&lt;/P&gt;

&lt;P&gt;Thank You&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 18:40:29 GMT</pubDate>
    <dc:creator>cdubs</dc:creator>
    <dc:date>2020-09-29T18:40:29Z</dc:date>
    <item>
      <title>ERROR TcpInputProc - Indexer not receiving data from forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Indexer-not-receiving-data-from-forwarder/m-p/288011#M55050</link>
      <description>&lt;P&gt;Hi all, I am getting these errors in my log files. First is from the spunkd.log from the indexer and second is is from the splunkd.log on the forwarder. I have done multiple searches on Splunk answers, but I haven't found one that pertain to both. It obvious in the error log on the forwarder that the connection is refused however I can telnet to the port 9997. What am I missing? This was all working until upgrading to 7.02. Thankfully this is just a test machine and not in production. Please let me know what I can provide you all to assist me in troubleshooting such as .conf/log files etc. I will continue to search &amp;amp; troubleshoot, but at this point I am loss.&lt;/P&gt;

&lt;P&gt;Splunk IDX Error:&lt;/P&gt;

&lt;P&gt;ERROR TcpInputProc - Message rejected. Received unexpected message of size=369295616 bytes from src=xxx.xx.xxx.xx:64529 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.&lt;/P&gt;

&lt;P&gt;ERROR TcpInputProc - Message rejected. Received unexpected message of size=369295616 bytes from src=xxx.xx.xxx.xx:61330 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.&lt;/P&gt;

&lt;P&gt;Splunk UF Error:&lt;/P&gt;

&lt;P&gt;WARN  TcpOutputProc - Applying quarantine to ip=xxx.xx.xxx.xx port=9997 _numberOfFailures=2&lt;BR /&gt;
WARN  TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group primary_indexers has been blocked for 3601 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;

&lt;P&gt;INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_xxx.xx.xxx.xx_8089_&lt;EM&gt;XA5D5CF2-F5DB-4F1F-BAE9-909B3A7FEA00&lt;BR /&gt;
INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_xxx.xx.xxx.xx_8089&lt;/EM&gt;_XA5D5CF2-F5DB-4F1F-BAE9-909B3A7FEA00&lt;/P&gt;

&lt;P&gt;WARN  TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group primary_indexers has been blocked for 3701 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;

&lt;P&gt;INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_xxx.xx.xxx.xx_8089_ _XA5D5CF2-F5DB-4F1F-BAE9-909B3A7FEA00&lt;/P&gt;

&lt;P&gt;WARN  TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group primary_indexers has been blocked for 3801 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;

&lt;P&gt;INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_xxx.xx.xxx.xx_8089_&lt;EM&gt;XA5D5CF2-F5DB-4F1F-BAE9-909B3A7FEA00&lt;BR /&gt;
INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_xxx.xx.xxx.xx_8089&lt;/EM&gt;&lt;EM&gt;XA5D5CF2-F5DB-4F1F-BAE9-909B3A7FEA00&lt;BR /&gt;
INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_xxx.xx.xxx.xx_8089&lt;/EM&gt;_XA5D5CF2-F5DB-4F1F-BAE9-909B3A7FEA00&lt;BR /&gt;
WARN  TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group primary_indexers has been blocked for 3901 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;

&lt;P&gt;INFO  TcpOutputProc - Removing quarantine from idx=xxx.xx.xxx.xx:9997&lt;/P&gt;

&lt;P&gt;ERROR TcpOutputFd - Connection to host=xxx.xx.xxx:9997 failed&lt;BR /&gt;
ERROR TcpOutputFd - Connection to host=xxx.xx.xxx:9997 failed&lt;/P&gt;

&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:40:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Indexer-not-receiving-data-from-forwarder/m-p/288011#M55050</guid>
      <dc:creator>cdubs</dc:creator>
      <dc:date>2020-09-29T18:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpInputProc - Indexer not receiving data from forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Indexer-not-receiving-data-from-forwarder/m-p/288012#M55051</link>
      <description>&lt;P&gt;Hi, will you be able to post the inputs.conf of indexer and outputs.conf of UF?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 03:36:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TcpInputProc-Indexer-not-receiving-data-from-forwarder/m-p/288012#M55051</guid>
      <dc:creator>Kendrick821</dc:creator>
      <dc:date>2018-03-26T03:36:18Z</dc:date>
    </item>
  </channel>
</rss>

