<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UF restarts due to TcpOutputProc issue in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/UF-restarts-due-to-TcpOutputProc-issue/m-p/465032#M8192</link>
    <description>&lt;P&gt;Hi all - anyone got any ideas please - MANY THANKS!&lt;/P&gt;</description>
    <pubDate>Wed, 27 May 2020 10:07:32 GMT</pubDate>
    <dc:creator>nickhaj</dc:creator>
    <dc:date>2020-05-27T10:07:32Z</dc:date>
    <item>
      <title>UF restarts due to TcpOutputProc issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/UF-restarts-due-to-TcpOutputProc-issue/m-p/465029#M8189</link>
      <description>&lt;P&gt;Hi - having issues with a Windows UF we are having to restart circa weekly to clear the issue below which happens at random times (the parsingQueue error being the first in the chain); the TcpOutProc errors continue until the UF is restarted. The amount of data being sent [hourly, on the hour] is very small.  Is this issue with the Forwarder or with the remote Splunk indexer, the forwarder seems to work OK at all other times ? NB : 'Phone Home' msgs removed. I can't see this exact scenario in other related Splunk Qs. MANY THANKS!!&lt;BR /&gt;
"05-14-2020 14:45:37.371 +0100 WARN  TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been blocked for 300 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data&lt;BR /&gt;
"05-14-2020 14:43:57.048 +0100 WARN  TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been blocked for 200 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data"05-14-2020 14:43:40.009 "05-14-2020 14:43:22.638 +0100 WARN  TailReader - Could not send data to output queue (parsingQueue), retrying...","2020-05-14T14:43:22.638+0100",PRDU0000001,"_internal",1,"C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log",splunkd&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 06:49:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/UF-restarts-due-to-TcpOutputProc-issue/m-p/465029#M8189</guid>
      <dc:creator>nickhaj</dc:creator>
      <dc:date>2020-05-26T06:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: UF restarts due to TcpOutputProc issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/UF-restarts-due-to-TcpOutputProc-issue/m-p/465031#M8191</link>
      <description>&lt;P&gt;Are you in the right forum ?? That wasnt the kind of answer I was expecting !!&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 08:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/UF-restarts-due-to-TcpOutputProc-issue/m-p/465031#M8191</guid>
      <dc:creator>nickhaj</dc:creator>
      <dc:date>2020-05-26T08:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: UF restarts due to TcpOutputProc issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/UF-restarts-due-to-TcpOutputProc-issue/m-p/465032#M8192</link>
      <description>&lt;P&gt;Hi all - anyone got any ideas please - MANY THANKS!&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 10:07:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/UF-restarts-due-to-TcpOutputProc-issue/m-p/465032#M8192</guid>
      <dc:creator>nickhaj</dc:creator>
      <dc:date>2020-05-27T10:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: UF restarts due to TcpOutputProc issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/UF-restarts-due-to-TcpOutputProc-issue/m-p/465033#M8193</link>
      <description>&lt;P&gt;Hi - ignoring the Answer below can anyone help please ? THANKS !!&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 13:01:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/UF-restarts-due-to-TcpOutputProc-issue/m-p/465033#M8193</guid>
      <dc:creator>nickhaj</dc:creator>
      <dc:date>2020-05-28T13:01:55Z</dc:date>
    </item>
  </channel>
</rss>

