Deployment Architecture

failing to send data from the windows 2012 R2 host to linux splunk indexer

Nadhiyag
Explorer

failing to send data from the windows 2012 R2 host to linux splunk indexer

Below is the error:
How to fix the error "The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been blocked for 6200 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data."

Telnet works fine

0 Karma

adonio
Ultra Champion

hello there,

please make sure you enable inputs on your Indexer as well as outputs on the correct port on the forwarder
also worthwhile to check there arent any blocks (firewall rules) on the way

more info here:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Troubleshooting/Cantfinddata

hope it helps

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...