Hey mates, I'm new to Splunk and while ingesting the data from my local machine to Splunk this message shows up.
"The TCP output processor has paused the data flow. Forwarding to host_dest=192.XXX.X.XX inside output group default-auto lb-group from host_src=MRNOOXX has been blocked for blocked_seconds=10. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data."
Kindly help me.
Thank you
The two previous posts both are good answers, but since you stated you are new to Splunk I decided to give you a thorough write up that explains how to check each of these areas that have been called out to see if they are the problem that is causing your error.
[tcpout:default-autolb-group] server = 192.XXX.X.XX:9997 disabled = 0
[tcpout] maxQueueSize = 100MB usePersistentQueue = true
For some reason, Splunk has stopped receiving data. It could be because of any of several reasons. Check the logs on indexer for possible explanations. Also, the Monitoring Console may offer clues - look for blocked indexer queues.
Hi @yash_eng
This warning indicates your forwarder cannot send data to the receiving Splunk instance at 192.XXX.X.XX because the connection is blocked or the receiver is not accepting data.
I'd recommend checking the following:
Can you give some more inforomation on your architecture / deployment setup? This might help pinpoint the possible issue, some common issues include; Receiver Splunk service is down, Firewall blocking the connection, Incorrect receiving port configuration, Network connectivity issues, Receiver disk space full or other resource constraints or SSL misconfiguration - if you're able to show us additional logs around the other errors this might also help.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing