<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The TCP output processor has paused the data flow. in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/526831#M9906</link>
    <description>&lt;P&gt;What are the correct settings for this?&amp;nbsp;&lt;SPAN&gt;pass4SymmKey values&amp;nbsp; ?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2020 11:11:13 GMT</pubDate>
    <dc:creator>Simons20</dc:creator>
    <dc:date>2020-10-28T11:11:13Z</dc:date>
    <item>
      <title>The TCP output processor has paused the data flow.</title>
      <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/509318#M9317</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i have the following error on my cluster masters (XXXXA13) web gui.&lt;BR /&gt;&lt;BR /&gt;Search peer XXXXP13 has the following message: The TCP output processor has paused the data flow. Forwarding to host_dest= inside output group group1 from host_src=XXXXP13 has been blocked for blocked_seconds=10. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data&lt;BR /&gt;&lt;BR /&gt;On the deployment server XXXXP13 i have the following error message on the web gui.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The TCP output processor has paused the data flow. Forwarding to host_dest= inside output group group1 from host_src=XXXXXP13 has been blocked for blocked_seconds=10. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data&lt;BR /&gt;&lt;BR /&gt;If i then have a look at splunkd on the deployment server i have the following errors&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;IndexerDiscoveryHeartbeatThread - Error in Indexer Discovery communication. Verify that the pass4SymmKey set under [indexer_discovery:group1] in 'outputs.conf' matches the same setting under [indexer_discovery] in 'server.conf' on the Cluster Master. [uri=https://XXXXXA13:8089/services/indexer_discovery http_code=502 http_response="Unauthorized"]&lt;BR /&gt;&lt;BR /&gt;WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to host_dest= inside output group group1 from host_src=XXXXXP13 has been blocked for blocked_seconds=158470. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;&lt;BR /&gt;Any help is greatly appreciated. This only happened after upgrading to 8.4.1&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 14:19:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/509318#M9317</guid>
      <dc:creator>willsy</dc:creator>
      <dc:date>2020-07-15T14:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: The TCP output processor has paused the data flow.</title>
      <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/509364#M9318</link>
      <description>Have you reviewed the system health in the Monitoring Console?&lt;BR /&gt;Have you verified the pass4SymmKey values are correct?</description>
      <pubDate>Wed, 15 Jul 2020 17:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/509364#M9318</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-15T17:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: The TCP output processor has paused the data flow.</title>
      <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/512022#M9391</link>
      <description>&lt;P&gt;So this is actually a really simple solution to one i believed to be alot harder.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;i checked all of my network firewalls, GPO firewalls, host based firewalls and it turned out the data diode was not actually accepting anything on that particular port.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I would also point out that if you are trying to send data from splunk to a third party i would HIGHLY advise going down the heavy forwarder route. much cleaner simpler and far far less hassle.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Aug 2020 17:01:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/512022#M9391</guid>
      <dc:creator>willsy</dc:creator>
      <dc:date>2020-08-01T17:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: The TCP output processor has paused the data flow.</title>
      <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/526831#M9906</link>
      <description>&lt;P&gt;What are the correct settings for this?&amp;nbsp;&lt;SPAN&gt;pass4SymmKey values&amp;nbsp; ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 11:11:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/526831#M9906</guid>
      <dc:creator>Simons20</dc:creator>
      <dc:date>2020-10-28T11:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: The TCP output processor has paused the data flow.</title>
      <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/570649#M13137</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/152686"&gt;@willsy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings, I'm new to Splunk.&lt;BR /&gt;Even we are having similar error on few HF "Error in Indexer Discovery communication" in an clustered environment. But there other HF in same cluster behaving normally.&amp;nbsp;&lt;BR /&gt;Recently, we updated/renewed SSL certificates on forwarding tier, indexing tier and on search tier.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 16:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/570649#M13137</guid>
      <dc:creator>anil19</dc:creator>
      <dc:date>2021-10-12T16:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: The TCP output processor has paused the data flow.</title>
      <link>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/570652#M13138</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232331"&gt;@anil19&lt;/a&gt;&amp;nbsp;This thread is over a year old with an accepted solution.&amp;nbsp; Please post a new question describing your problem.&amp;nbsp; You can refer to this thread and tell how the solution doesn't help in your case.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 16:41:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/The-TCP-output-processor-has-paused-the-data-flow/m-p/570652#M13138</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-12T16:41:29Z</dc:date>
    </item>
  </channel>
</rss>

