Splunk Cloud Platform

TCPOutAutoLB-0 after installing UF credentials from Splunk cloud

ejose
Explorer

Hi,

We have Splunk Enterprise 9.3.1 that we use as a Heavy Forwarder that sends data to Splunk Cloud indexers using the UF credentials downloaded from the Splunk Cloud instance. After upgrading to 9.4.0, we started getting TCPOutAutoLB-0 error messages in the HF.

We tried installing a fresh 9.4.0 and 9.4.1 and just installing the UF certificate and we still get the error. Installing a fresh 9.3.1 with the same certificate does not have the error.

Has any one experienced the same problem? How were you able to fix it?

Regards,

Edward

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The first thing to check is the splunkd.log on the problematic (sending) machine. It should tell you if the connection is established at all or if it's being actively rejected or anythin else.

0 Karma

ejose
Explorer

Hi,

The problem seems to be the self signed certificate that was issued by Splunk from the cloud instance. It is not compatible with ver 9.4.

I was wondering if it was just me who is experiencing the issue or if some one else is experiencing it.

But for now we are sticking with ver 9.3.1 in our HF until a fix is released by Splunk.

 

livehybrid
SplunkTrust
SplunkTrust

Hi @ejose 

Please could you share the errors that you are receiving.

Can you also confirm the certificate has not expired? The reason I ask this specifically is that a Splunk forwarder will remain connected to another Splunk server even after an SSL cert has expired if it cannot create a new connection. In other words, its possible the certificate had previously expired but you only experienced an issue once the existing connection was closed down and you upgraded. 

openssl x509 -in <PathToYourCert> -noout -dates

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

ejose
Explorer

Hi,

I can confirm that the certificate is valid. We have use the same certificate on Splunk ver 9.3 and we don't get the TCPOutAutoLB-0 error. It only happens on ver 9.4.x

0 Karma

kiran_panchavat
Champion

@ejose 

Check this 

https://community.splunk.com/t5/Getting-Data-In/How-to-fix-Heavy-Forwarder-to-Splunk-Cloud-logs-forw... 

https://community.splunk.com/t5/Getting-Data-In/How-to-fix-TCPOutAutoLB-0-error/m-p/613119 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...