Deployment Architecture

Heavy Forwarder TcpOutputProc output queue is not sending to AIO

stromy
Loves-to-Learn Lots

Dears

Thanks A lot for helping Already.

i have 2 heavy forwarders(HF) and one Indexer(AIO)
Im facing this issue for the first time,(HF-1) is not forwarding logs to AIO , though HF-2 is sending normally to the AIO and i can search the logs .

The thing is i tried telnet on both sides it did connect, it seems there is no network problem, firewall is down, SElinux is down
below are some logs on the HF-1

03-14-2020 02:00:54.097 +0300 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group primary_indexers has been blocked for 230 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.

03-14-2020 01:23:22.056 +0300 WARN TcpOutputProc - Read operation timed out expecting ACK from 10.244.2.100:9997 in 300 seconds.

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...