this message is displaying in the splunkd logs on syslog server.
we are forwarding data from syslog server to DMZ server as we are getting logs from outside our network. And then to indexer.
Hey Hi,
I did encounter this issue a couple of times and it happened to be a connectivity issue where the Comms between source and destination wasn't enabled and firewall was blocking it. If this is the route taken: Syslog server -> DMZ server -> Indexers, then checking the following may help.
Hi @SN1
Are you able to confirm if the input queue was blocked on the receiving server (e.g. another HF or your indexer)? The log suggests that for a small period of time it could not connect to the indexer/HF.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing