I have been getting this warning event on one of my Splunk instance (Role - Deployment Server + License Master)
Architecture is as below-
Deployement Server > HF1 and HF2 > Indexers
Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been block for X seconds. This will probably stall the data flow towards indexing and other outputs. Review the receiving system’s health in the Splunk Monitoring Console. It is probably not accepting data.
Usually it means that there are performance issue on indexer side. You can figure it with Monitoring Console. If you have configured it then use it otherwise you need to use some queries or use it in all indexers. I assume that you have installed&configured MC on place (or you will do it).
Open MC -> Indexing -> Indexing Performance: Deployment.
That shows how indexing is working on your environment. It shows which indexer is the bottle neck or is there several ones. After you see which one is busiest then select it and look instance performance which shows in which part of pipeline has stucked. Based on that the fix is little bit different.
This error/warning is ok, if it arise time by time and not too often.