<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The TCP output processor has paused the data flow. in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755155#M16348</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313982"&gt;@Rushilgupta02&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Firewall/SELinux reset happened after patching? Did you restart UF after patching? Sometimes UF service may not restart cleanly during patching.&amp;nbsp;Also verify DNS resolution for&amp;nbsp;proxy.splunk.local&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 04 Nov 2025 09:25:34 GMT</pubDate>
    <dc:creator>PrewinThomas</dc:creator>
    <dc:date>2025-11-04T09:25:34Z</dc:date>
    <item>
      <title>The TCP output processor has paused the data flow.</title>
      <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755148#M16345</link>
      <description>&lt;P&gt;After my system gets patched, connection from host (nginx servers) to splunk gets cut (sometimes). This causes logs to not get populated on splunk. For example- I have 5 nginx servers, all of them get patched but 3 of them loose connection and this is random. I have pasted my logs down below, any guidance on how to fix this issue?&lt;BR /&gt;&lt;BR /&gt;Logs-&lt;BR /&gt;11-02-2025 03:19:19.345 +0000 INFO AutoLoadBalancedConnectionStrategy [3292 TcpOutEloop] - Connected to idx=1x.xxx.x.x:9997:3, pset=0, reuse=0. autoBatch=1&lt;BR /&gt;11-02-2025 03:19:49.245 +0000 INFO AutoLoadBalancedConnectionStrategy [3292 TcpOutEloop] - Connected to idx=1x.xxx.x.x:9997:3, pset=0, reuse=0. autoBatch=1&lt;BR /&gt;11-02-2025 03:20:00.697 +0000 INFO DC:DeploymentClient [3141 PhonehomeThread] - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;11-02-2025 03:20:07.945 +0000 WARN TcpOutputProc [3289 parsing] - The TCP output processor has paused the data flow. Forwarding to host_dest=proxy.splunk.local inside output group nginx from host_src=us-ng3 has been blocked for blocked_seconds=18400. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 07:21:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755148#M16345</guid>
      <dc:creator>Rushilgupta02</dc:creator>
      <dc:date>2025-11-04T07:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: The TCP output processor has paused the data flow.</title>
      <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755149#M16346</link>
      <description>&lt;P&gt;adding to this, all my ports are open, firewall is fine.....there should be no changes other than the ec2 instance rebooting.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 07:29:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755149#M16346</guid>
      <dc:creator>Rushilgupta02</dc:creator>
      <dc:date>2025-11-04T07:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: The TCP output processor has paused the data flow.</title>
      <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755151#M16347</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313982"&gt;@Rushilgupta02&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;did you checked the local firewalls on the&amp;nbsp;&lt;SPAN&gt;nginx servers?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 07:33:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755151#M16347</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-11-04T07:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: The TCP output processor has paused the data flow.</title>
      <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755155#M16348</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313982"&gt;@Rushilgupta02&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Firewall/SELinux reset happened after patching? Did you restart UF after patching? Sometimes UF service may not restart cleanly during patching.&amp;nbsp;Also verify DNS resolution for&amp;nbsp;proxy.splunk.local&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 09:25:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755155#M16348</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-11-04T09:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: The TCP output processor has paused the data flow.</title>
      <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755224#M16349</link>
      <description>What you actually mean with this "connection from host (nginx servers) to splunk gets cut (sometimes)."?&lt;BR /&gt;Is the connection always down, will it start to working after some time or after something has done? Or something else?</description>
      <pubDate>Wed, 05 Nov 2025 14:33:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755224#M16349</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-11-05T14:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: The TCP output processor has paused the data flow.</title>
      <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755319#M16350</link>
      <description>&lt;P&gt;Hi. What version of Splunk are you running?&lt;BR /&gt;&lt;BR /&gt;I ran into a bad bug with both Splunk Enterprise 9.3.7 and 9.4.5. The heavy forwarders sending to DNS load balanced indexers get TCPOUT blocked.&amp;nbsp; This bug does not appear to be on the known issues despite many attempts by me trying to get it added there. It does not happen with 9.2.4.&lt;BR /&gt;&lt;BR /&gt;The Splunk JIRA that was opened is&amp;nbsp;&lt;SPAN&gt;SPL-288904&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;The bug is said to be fixed in the upcoming releases&amp;nbsp;&lt;STRONG&gt;9.3.9 , 9.4.7, 10.0.3, 10.1&lt;BR /&gt;&lt;/STRONG&gt;Hopefully soon.&lt;BR /&gt;&lt;BR /&gt;A workaround is the setting of&amp;nbsp;&lt;SPAN&gt;dnsResolutionInterval in outputs.conf&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;dnsResolutionInterval = &amp;lt;integer&amp;gt;
* The base time interval, in seconds, at which indexer Domain Name Server
  (DNS) names are resolved to IP addresses.
* This is used to compute runtime dnsResolutionInterval as follows:
  Runtime interval =
   'dnsResolutionInterval' + (number of indexers in server settings - 1) * 30.
* The DNS resolution interval is extended by 30 seconds for each additional
  indexer in the server setting.
* Default: 300 seconds (5 minutes)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk had recommended we set dnsResolutionInterval =480 (tcpout blocked). I tried 1000 (also blocked).&amp;nbsp;&lt;BR /&gt;I have set it to 10000 (ie 10,000) and after ~ 3 days this seems to be working.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2025 18:21:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/755319#M16350</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2025-11-07T18:21:21Z</dc:date>
    </item>
  </channel>
</rss>

