More than 70% of forwarding destinations have failed. Ensure your hosts and ports in outputs.conf are correct. Also ensure that the indexers are all running, and that any SSL certificates being used for forwarding are correct.
Is this a question or help for another reader?
It's a poorly worded question, sorry. Processing keeps being paused and my health message provides this message:
More than 70% of forwarding destinations have failed. Ensure your hosts and ports in outputs.conf are correct. Also ensure that the indexers are all running, and that any SSL certificates being used for forwarding are correct.
I installed Splunk Enterprise and then implemented SSL for splunkWeb and am unable to get events consumed. I'm thinking it's because I need to configure SSL in my inputs.conf for the indexer and in my outputs.conf for the forwarders but I don't know for sure.
If that's the case, I've found splunk docs that should guide me through. But maybe there's another problem?