Getting Data In

Restarting Splunk UF due to TcpOutputProc issues

nickhaj
New Member

Hi - having issues with a Windows UF we are having to restart circa weekly to clear the issue below which happens at random times (the parsingQueue error being the first in the chain); the TcpOutProc errors continue until the UF is restarted. The amount of data being sent [hourly, on the hour] is very small. Is this issue with the Forwarder or with the remote Splunk indexer, the forwarder seems to work OK at all other times ? NB : 'Phone Home' msgs removed. I can't see this exact scenario in other related Splunk Qs. MANY THANKS!!
"05-14-2020 14:45:37.371 +0100 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been blocked for 300 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data
"05-14-2020 14:43:57.048 +0100 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been blocked for 200 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data"05-14-2020 14:43:40.009 "05-14-2020 14:43:22.638 +0100 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...","2020-05-14T14:43:22.638+0100",PRDU0000001,"_internal",1,"C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log",splunkd

Labels (2)
0 Karma

gjanders
SplunkTrust
SplunkTrust
0 Karma

nickhaj
New Member

Hi - we upgraded the Forwarder to Version 7.3.6 (For W2012 svr) from 7.3.0 in the the hope this would cure the problem with the Forwarder restarts per the release notes below, but the issue outlined previously has occurred again.

Can you just confirm this is definitely a problem at the UF end rather than at the Indexer end given the nature of the error ? Many Thanks!

2020-05-07SPL-188620, SPL-184263UFs stop forwarding after some time and need constant restarting
Tags (1)
0 Karma

nickhaj
New Member

Can anyone advise on this issue please ???

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...