Getting Data In

Issue While Onboarding the Data into Splunk Cloud

anandhalagarasa
Path Finder

I am new to Splunk Cloud. Recently we have purchased Splunk Cloud for our organization and I have got the Splunk Cloud URL as provided by the Support.

Post which I have tried to ingest some logs from a server into Splunk cloud by navigating to Splunk Cloud URL->Universal Forwarder. And I have followed the exact steps as mentioned in the below URL:

https://docs.splunk.com/Documentation/SplunkCloud/7.1.3/User/ForwardDataToSplunkCloudFromWindows

I have downloaded and installed the UF in the machine. Then have downloaded the splunkclouduf.spl file and installed as mentioned. And restarted the Splunk Forwarder services but still I couldn’t able to see any internal logs for the server itself.

When I search the data for last 30 minutes as index=_internal I am getting the results for Indexers, Search Head and so on but not for the particular host which we have installed with UF.

And also when I checked the splunkd.log of the particular host I am getting these messages.

TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group splunkcloud has been blocked for 61300 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.

Tags (1)
0 Karma

woodcock
Esteemed Legend

By default the data comes in on port 9997 for non-SSL and 9998 for SSL. Check for firewall blocks on those ports. This kind of thing is almost always the firewall.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...