Getting Data In

Error on forwarder

bosseres
Contributor

Hello everyone,

I'm trying to configure deployment server and i have a error, occured on forwarder

TCPOutAutoLB-1

  • Root Cause(s):
    • More than 70% of forwarding destinations have failed. Ensure your hosts and ports in outputs.conf are correct. Also ensure that the indexers are all running, and that any SSL certificates being used for forwarding are correct.
  • Last 50 related messages:
    • 01-26-2021 14:55:56.254 +0300 WARN TcpOutputProc - Applying quarantine to ip=10.22.31.80 port=9997 _numberOfFailures=2
    • 01-26-2021 14:55:56.253 +0300 INFO TcpOutputProc - Found currently active indexer. Connected to idx=10.22.22.241:9997, reuse=1.
    • 01-26-2021 14:55:26.660 +0300 INFO TcpOutputProc - Connected to idx=10.22.22.241:9997, pset=0, reuse=0.
    • 01-26-2021 14:55:26.553 +0300 INFO TcpOutputProc - _isHttpOutConfigured=NOT_CONFIGURED
    • 01-26-2021 14:55:26.322 +0300 INFO TcpOutputProc - Group receiver initialized with maxQueueSize=512000 in bytes.

What does it mean? Thank you.

Labels (1)
0 Karma

bosseres
Contributor

we can close topic, I resolved the problem

ty

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @bosseres,

check the connection between Ds and Indexers because probably there a block between them.

You could use telnet:

telnet 10.22.31.80 9997
telnet 10.22.22.241 9997

If telnet fails, you can check:

  • local firewall on DS,
  • firewalls between Ds and Indexers,
  • enabled receiving (on port 9997) on Indexers.

Ciao.

Giuseppe

bosseres
Contributor

one more question, why can't I delete host from list? there is really no such host in outputs.conf

bosseres_0-1611662382550.png

 

0 Karma

bosseres
Contributor

second one question I resolved with btool

Tags (1)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...