Deployment Architecture

Splunk indexing is not working

manjunathaya
New Member

Team,

Geeting below error while indexing. Please let me know how can we fix this?

11-25-2019 07:39:35.796 -0500 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to host_dest=vc2crtp1428667np.fmr.com inside output group rtpindexer from host_src=vc2coma2429304n.fmr.com has been blocked
for blocked_seconds=600. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.

Tags (1)
0 Karma

oscar84x
Contributor

Do you have any forwarders working successfully, so that you can compare configurations?
What does your outputs and inputs look like?
Is the Indexer(s) expecting SSL?
Could also be a network issue, is the port open on the receiving end?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...