<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cant get windows server into splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cant-get-windows-server-into-splunk/m-p/531224#M89375</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229217"&gt;@davidbeiler&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;only one question: after the pause, you continued to have logs from this server or they stopped?&lt;/P&gt;&lt;P&gt;if they continued to arrive (eventually late) probably there was a temporary network congestion caused by the network and/or the data flow (I don't think because this seems a lab configuration) or more probably by the index queue caused by the storage performances.&lt;/P&gt;&lt;P&gt;If instead they don't arrive more, there's something in the middle that blocks the data flow:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;are there other forwarders that are sending logs?&lt;/LI&gt;&lt;LI&gt;did you tested with telnet the connection on port 9997?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Sat, 28 Nov 2020 07:26:51 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-11-28T07:26:51Z</dc:date>
    <item>
      <title>Cant get windows server into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cant-get-windows-server-into-splunk/m-p/531220#M89373</link>
      <description>&lt;P&gt;Im pretty technical... i got splunk installed in centos, everything works ok, but for the life of me i cant figure this out&lt;/P&gt;&lt;P&gt;11-27-2020 23:53:54.093 -0500 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to host_dest=192.168.1.109 inside output group default-autolb-group from host_src=splunk has been blocked for blocked_seconds=710. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;&lt;P&gt;Ports are open for 8000, 9997 (receiving port), and opened 8089.&amp;nbsp; Plenty of disk space, though when i do ss -l | grep 9997 i do not see anything for port 9997, even though ive unblocked the port 1000 times&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2020 05:10:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cant-get-windows-server-into-splunk/m-p/531220#M89373</guid>
      <dc:creator>davidbeiler</dc:creator>
      <dc:date>2020-11-28T05:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cant get windows server into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cant-get-windows-server-into-splunk/m-p/531224#M89375</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229217"&gt;@davidbeiler&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;only one question: after the pause, you continued to have logs from this server or they stopped?&lt;/P&gt;&lt;P&gt;if they continued to arrive (eventually late) probably there was a temporary network congestion caused by the network and/or the data flow (I don't think because this seems a lab configuration) or more probably by the index queue caused by the storage performances.&lt;/P&gt;&lt;P&gt;If instead they don't arrive more, there's something in the middle that blocks the data flow:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;are there other forwarders that are sending logs?&lt;/LI&gt;&lt;LI&gt;did you tested with telnet the connection on port 9997?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2020 07:26:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cant-get-windows-server-into-splunk/m-p/531224#M89375</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-11-28T07:26:51Z</dc:date>
    </item>
  </channel>
</rss>

