Deployment Architecture

Heavy Forwarder TcpOutputProc output queue is not sending to AIO

stromy
Loves-to-Learn Lots

Dears

Thanks A lot for helping Already.

i have 2 heavy forwarders(HF) and one Indexer(AIO)
Im facing this issue for the first time,(HF-1) is not forwarding logs to AIO , though HF-2 is sending normally to the AIO and i can search the logs .

The thing is i tried telnet on both sides it did connect, it seems there is no network problem, firewall is down, SElinux is down
below are some logs on the HF-1

03-14-2020 02:00:54.097 +0300 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group primary_indexers has been blocked for 230 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.

03-14-2020 01:23:22.056 +0300 WARN TcpOutputProc - Read operation timed out expecting ACK from 10.244.2.100:9997 in 300 seconds.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...