Hi @isoutamo, thank for your help! Yes I already saw the above link, for this reason I opened the case: because in the url is described an action on the search head, but I don't have SHs and in HFs...
See more...
Hi @isoutamo, thank for your help! Yes I already saw the above link, for this reason I opened the case: because in the url is described an action on the search head, but I don't have SHs and in HFs distsearch.conf there isn't the described lines. I suppose that's a quarantine issue because I have many messages in splunkd.log that speaks of quarantined files, but I don't know how to unquarantine the machine. I'm waiting for the call from Splunk Support, hoping that they can guide me. Have you never exeperienced this issue? Local MC doesn't give any quarantine message, only that "the downstream queue is not accepting data", but I can reach Splunk Cloud by telnet, so it isn't a firewall issue. Thank you again, please hint every check that you can think (if you have). Ciao. Giuseppe