Splunk Cloud Platform

TCPOutAutoLB-0 after installing UF credentials from Splunk cloud

ejose
Explorer

Hi,

We have Splunk Enterprise 9.3.1 that we use as a Heavy Forwarder that sends data to Splunk Cloud indexers using the UF credentials downloaded from the Splunk Cloud instance. After upgrading to 9.4.0, we started getting TCPOutAutoLB-0 error messages in the HF.

We tried installing a fresh 9.4.0 and 9.4.1 and just installing the UF certificate and we still get the error. Installing a fresh 9.3.1 with the same certificate does not have the error.

Has any one experienced the same problem? How were you able to fix it?

Regards,

Edward

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The first thing to check is the splunkd.log on the problematic (sending) machine. It should tell you if the connection is established at all or if it's being actively rejected or anythin else.

0 Karma

ejose
Explorer

Hi,

The problem seems to be the self signed certificate that was issued by Splunk from the cloud instance. It is not compatible with ver 9.4.

I was wondering if it was just me who is experiencing the issue or if some one else is experiencing it.

But for now we are sticking with ver 9.3.1 in our HF until a fix is released by Splunk.

 

livehybrid
SplunkTrust
SplunkTrust

Hi @ejose 

Please could you share the errors that you are receiving.

Can you also confirm the certificate has not expired? The reason I ask this specifically is that a Splunk forwarder will remain connected to another Splunk server even after an SSL cert has expired if it cannot create a new connection. In other words, its possible the certificate had previously expired but you only experienced an issue once the existing connection was closed down and you upgraded. 

openssl x509 -in <PathToYourCert> -noout -dates

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

ejose
Explorer

Hi,

I can confirm that the certificate is valid. We have use the same certificate on Splunk ver 9.3 and we don't get the TCPOutAutoLB-0 error. It only happens on ver 9.4.x

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@ejose 

Check this 

https://community.splunk.com/t5/Getting-Data-In/How-to-fix-Heavy-Forwarder-to-Splunk-Cloud-logs-forw... 

https://community.splunk.com/t5/Getting-Data-In/How-to-fix-TCPOutAutoLB-0-error/m-p/613119 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...