Getting Data In

Issue While Onboarding the Data into Splunk Cloud

anandhalagarasa
Path Finder

I am new to Splunk Cloud. Recently we have purchased Splunk Cloud for our organization and I have got the Splunk Cloud URL as provided by the Support.

Post which I have tried to ingest some logs from a server into Splunk cloud by navigating to Splunk Cloud URL->Universal Forwarder. And I have followed the exact steps as mentioned in the below URL:

https://docs.splunk.com/Documentation/SplunkCloud/7.1.3/User/ForwardDataToSplunkCloudFromWindows

I have downloaded and installed the UF in the machine. Then have downloaded the splunkclouduf.spl file and installed as mentioned. And restarted the Splunk Forwarder services but still I couldn’t able to see any internal logs for the server itself.

When I search the data for last 30 minutes as index=_internal I am getting the results for Indexers, Search Head and so on but not for the particular host which we have installed with UF.

And also when I checked the splunkd.log of the particular host I am getting these messages.

TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group splunkcloud has been blocked for 61300 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.

Tags (1)
0 Karma

woodcock
Esteemed Legend

By default the data comes in on port 9997 for non-SSL and 9998 for SSL. Check for firewall blocks on those ports. This kind of thing is almost always the firewall.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...