Getting Data In

just started learning splunk

deepmis
New Member

How do I resolve this error -> happens with both linux and mac

The TCP output processor has paused the data flow. Forwarding to host_dest=192.168.1.5 inside output group default-autolb-group from host_src=MacBook-Air.local has been blocked for blocked_seconds=10. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @deepmis,

the message you have means that the client cannot reach to send logs to the indexer because it's closed the connection.

At first a stupid question. di you enabled receiving on Indexer? on port 9997?

If yes, try using telnet to see if the connection is open from the client to the indexer:

telnet ip_indexer 9997

then verify that the IP addresses of your computers are in the same network.

Ciao.

Giuseppe

0 Karma

saravanan90
Contributor

Mostly this could be firewall issue. Check the host firewall by connecting to destination server.
From forwarder we can telnet to destination to confirm the same

telnet indexer 9997

0 Karma

deepmis
New Member

There is no firewall .. its a home computer

0 Karma

saravanan90
Contributor

Check the firewall communication.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...