Deployment Architecture

Splunk indexing is not working

manjunathaya
New Member

Team,

Geeting below error while indexing. Please let me know how can we fix this?

11-25-2019 07:39:35.796 -0500 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to host_dest=vc2crtp1428667np.fmr.com inside output group rtpindexer from host_src=vc2coma2429304n.fmr.com has been blocked
for blocked_seconds=600. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.

Tags (1)
0 Karma

oscar84x
Contributor

Do you have any forwarders working successfully, so that you can compare configurations?
What does your outputs and inputs look like?
Is the Indexer(s) expecting SSL?
Could also be a network issue, is the port open on the receiving end?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...