<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk universal forwarder not able to send logs to Indexers in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-not-able-to-send-logs-to-Indexers/m-p/425372#M95300</link>
    <description>&lt;P&gt;HI Team, &lt;/P&gt;

&lt;P&gt;I have installed Splunk enterprise Indexers version 7.16 and Splunk UFD version 7.2.5 but I am seeing below errors in the logs and logs are not getting forwarded to Indexers. Can you please help with the fix&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Errors on UFD: &lt;BR /&gt;
04-24-2019 18:14:28.351 +0000 ERROR TcpOutputFd - Connection to host=10.10.10.1:9997 failed&lt;BR /&gt;
04-24-2019 18:14:28.351 +0000 WARN  TcpOutputProc - Applying quarantine to ip=10.10.10.1 port=9997 _numberOfFailures=2&lt;BR /&gt;
04-24-2019 18:15:29.749 +0000 WARN  TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been blocked for 1300 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;
04-24-2019 18:18:49.772 +0000 WARN  TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been blocked for 1500 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data&lt;/P&gt;

&lt;P&gt;Errors on Indexer: &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;04-24-2019 18:19:13.854 +0000 ERROR TcpInputProc - Message rejected. Received unexpected message of size=369295616 bytes from src=10.117.139.213:59565 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.&lt;BR /&gt;
04-24-2019 18:19:13.860 +0000 ERROR TcpInputProc - Message rejected. Received unexpected message of size=369295616 bytes from src=10.117.139.213:59570 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2019 18:31:10 GMT</pubDate>
    <dc:creator>pkumar9610</dc:creator>
    <dc:date>2019-04-24T18:31:10Z</dc:date>
    <item>
      <title>Splunk universal forwarder not able to send logs to Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-not-able-to-send-logs-to-Indexers/m-p/425372#M95300</link>
      <description>&lt;P&gt;HI Team, &lt;/P&gt;

&lt;P&gt;I have installed Splunk enterprise Indexers version 7.16 and Splunk UFD version 7.2.5 but I am seeing below errors in the logs and logs are not getting forwarded to Indexers. Can you please help with the fix&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Errors on UFD: &lt;BR /&gt;
04-24-2019 18:14:28.351 +0000 ERROR TcpOutputFd - Connection to host=10.10.10.1:9997 failed&lt;BR /&gt;
04-24-2019 18:14:28.351 +0000 WARN  TcpOutputProc - Applying quarantine to ip=10.10.10.1 port=9997 _numberOfFailures=2&lt;BR /&gt;
04-24-2019 18:15:29.749 +0000 WARN  TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been blocked for 1300 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;
04-24-2019 18:18:49.772 +0000 WARN  TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been blocked for 1500 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data&lt;/P&gt;

&lt;P&gt;Errors on Indexer: &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;04-24-2019 18:19:13.854 +0000 ERROR TcpInputProc - Message rejected. Received unexpected message of size=369295616 bytes from src=10.117.139.213:59565 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.&lt;BR /&gt;
04-24-2019 18:19:13.860 +0000 ERROR TcpInputProc - Message rejected. Received unexpected message of size=369295616 bytes from src=10.117.139.213:59570 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 18:31:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-not-able-to-send-logs-to-Indexers/m-p/425372#M95300</guid>
      <dc:creator>pkumar9610</dc:creator>
      <dc:date>2019-04-24T18:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder not able to send logs to Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-not-able-to-send-logs-to-Indexers/m-p/425373#M95301</link>
      <description>&lt;P&gt;I am able to telnet and nslookup from UFD to Indexer machine. And I can see 9997 port is also open on Indexer&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 18:38:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-not-able-to-send-logs-to-Indexers/m-p/425373#M95301</guid>
      <dc:creator>pkumar9610</dc:creator>
      <dc:date>2019-04-24T18:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder not able to send logs to Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-not-able-to-send-logs-to-Indexers/m-p/425374#M95302</link>
      <description>&lt;P&gt;Hi  pkumar9610,&lt;BR /&gt;
when you say Splunk Indexers version is 7.16, are you sayng 7.1.6?&lt;BR /&gt;
if this is your situation, remember that UF version must be the same or older than Indexer version.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2019 07:35:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-not-able-to-send-logs-to-Indexers/m-p/425374#M95302</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-04-25T07:35:35Z</dc:date>
    </item>
  </channel>
</rss>

