Getting Data In

Issue While Onboarding the Data into Splunk Cloud

anandhalagarasa
Path Finder

I am new to Splunk Cloud. Recently we have purchased Splunk Cloud for our organization and I have got the Splunk Cloud URL as provided by the Support.

Post which I have tried to ingest some logs from a server into Splunk cloud by navigating to Splunk Cloud URL->Universal Forwarder. And I have followed the exact steps as mentioned in the below URL:

https://docs.splunk.com/Documentation/SplunkCloud/7.1.3/User/ForwardDataToSplunkCloudFromWindows

I have downloaded and installed the UF in the machine. Then have downloaded the splunkclouduf.spl file and installed as mentioned. And restarted the Splunk Forwarder services but still I couldn’t able to see any internal logs for the server itself.

When I search the data for last 30 minutes as index=_internal I am getting the results for Indexers, Search Head and so on but not for the particular host which we have installed with UF.

And also when I checked the splunkd.log of the particular host I am getting these messages.

TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group splunkcloud has been blocked for 61300 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.

Tags (1)
0 Karma

woodcock
Esteemed Legend

By default the data comes in on port 9997 for non-SSL and 9998 for SSL. Check for firewall blocks on those ports. This kind of thing is almost always the firewall.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...