<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder - Repeating message TcpOutputProc - Found currently active indexer... in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/531299#M89386</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/57862"&gt;@dlpco&lt;/a&gt;&amp;nbsp; Try downgrading the UF to version 8.0.1. It solved my problems. I also noticed, that all the logs were not transported to the indexer during the error messages. With UF v. 8.0.1 normal operation was resumed.&lt;/P&gt;&lt;P&gt;Br, Petri&lt;/P&gt;</description>
    <pubDate>Mon, 30 Nov 2020 09:50:49 GMT</pubDate>
    <dc:creator>kaurinko</dc:creator>
    <dc:date>2020-11-30T09:50:49Z</dc:date>
    <item>
      <title>Universal Forwarder - Repeating message TcpOutputProc - Found currently active indexer...</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/469302#M80746</link>
      <description>&lt;P&gt;I am getting the following messages on my forwarder running on Windows 10:&lt;/P&gt;

&lt;P&gt;04-06-2020 18:05:52.171 -0700 INFO  TcpOutputProc - Found currently active indexer. Connected to idx=192.168.218.6:9997, reuse=1.&lt;BR /&gt;
04-06-2020 18:06:22.093 -0700 INFO  TcpOutputProc - Found currently active indexer. Connected to idx=192.168.218.6:9997, reuse=1.&lt;BR /&gt;
04-06-2020 18:06:51.934 -0700 INFO  TcpOutputProc - Found currently active indexer. Connected to idx=192.168.218.6:9997, reuse=1.&lt;BR /&gt;
04-06-2020 18:07:21.808 -0700 INFO  TcpOutputProc - Found currently active indexer. Connected to idx=192.168.218.6:9997, reuse=1.&lt;BR /&gt;
04-06-2020 18:07:51.660 -0700 INFO  TcpOutputProc - Found currently active indexer. Connected to idx=192.168.218.6:9997, reuse=1.&lt;/P&gt;

&lt;P&gt;I just updated the forwarder to 8.0.3 and these messages just keep coming.  There are no disconnect messages, just these found messages.&lt;/P&gt;

&lt;P&gt;HELP...&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 01:20:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/469302#M80746</guid>
      <dc:creator>dlpco</dc:creator>
      <dc:date>2020-04-07T01:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder - Repeating message TcpOutputProc - Found currently active indexer...</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/469303#M80747</link>
      <description>&lt;P&gt;Those entries are normal and indicate successful connection between forwarder and indexer. Nothing to be concerned about, the opposite actually.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2020 16:20:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/469303#M80747</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2020-04-17T16:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder - Repeating message TcpOutputProc - Found currently active indexer...</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/530527#M89304</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also get these messages, 410.000 times in 4 hours and splunkd is the most indexed data type when I look in the monitoring console.&lt;/P&gt;&lt;P&gt;Is this normal? (I have around 800 forwarders in total)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Daniel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 05:46:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/530527#M89304</guid>
      <dc:creator>daniellange</dc:creator>
      <dc:date>2020-11-24T05:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder - Repeating message TcpOutputProc - Found currently active indexer...</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/530827#M89326</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I noticed by accident I also had this problem, and it all started when I upgraded the Universal Forwaders to version 8.1.0. Now I downgraded all UFs back to version 8.0.1 and the problems disappeared. The Indexer version was originally when the problems started to appear 8.1.0, and right now it is 8.1.0.1.&lt;BR /&gt;&lt;BR /&gt;For me this was not only an annoyance. I first found the problem, when I realized some logs were not transferred to the indexer. Some trouble shooting took me to the UF version issue. In my opinion this is clearly a bug, and it should be fixed.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;&lt;BR /&gt;Petri&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 14:07:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/530827#M89326</guid>
      <dc:creator>kaurinko</dc:creator>
      <dc:date>2020-11-25T14:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder - Repeating message TcpOutputProc - Found currently active indexer...</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/531299#M89386</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/57862"&gt;@dlpco&lt;/a&gt;&amp;nbsp; Try downgrading the UF to version 8.0.1. It solved my problems. I also noticed, that all the logs were not transported to the indexer during the error messages. With UF v. 8.0.1 normal operation was resumed.&lt;/P&gt;&lt;P&gt;Br, Petri&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 09:50:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/531299#M89386</guid>
      <dc:creator>kaurinko</dc:creator>
      <dc:date>2020-11-30T09:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder - Repeating message TcpOutputProc - Found currently active indexer...</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/680757#M113729</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/139659"&gt;@codebuilder&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;i got the same message, but in the splunk i don't find any logs.&lt;BR /&gt;What is the problem ?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 22:30:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Repeating-message-TcpOutputProc-Found/m-p/680757#M113729</guid>
      <dc:creator>Navaneedhan</dc:creator>
      <dc:date>2024-03-14T22:30:28Z</dc:date>
    </item>
  </channel>
</rss>

