Unfortunately I will not be able to answer all your questions. Splunk is installed on the Nextcloud server according to the instructions, except for this, nothing else has been configured by splunk. When I started splunkforwarder, I got an error that port 8089 is busy and I changed it to 9089. Here is the data from the Monitoring Console and splunk.log. I hope I understood you correctly and sent the necessary data. https://intranet.graabek.com/cloud/index.php/s/Lc9oXkaWNmQHBqG#pdfviewer 07-17-2020 16:08:35.807 +0300 INFO TcpOutputProc - Removing quarantine from idx=127.0.0.1:9997 07-17-2020 16:08:35.807 +0300 WARN TcpOutputFd - Connect to 127.0.0.1:9997 failed. Connection refused 07-17-2020 16:08:35.807 +0300 ERROR TcpOutputFd - Connection to host=127.0.0.1:9997 failed 07-17-2020 16:08:35.807 +0300 WARN TcpOutputFd - Connect to 127.0.0.1:9997 failed. Connection refused 07-17-2020 16:08:35.807 +0300 ERROR TcpOutputFd - Connection to host=127.0.0.1:9997 failed 07-17-2020 16:08:35.807 +0300 WARN TcpOutputProc - Applying quarantine to ip=127.0.0.1 port=9997 _numberOfFailures=2 07-17-2020 16:09:55.913 +0300 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to host_dest=127.0.0.1 inside output group default-autolb-group from host_src=Nextcloud has been blocked for blocked_seconds=10600. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data. 07-17-2020 16:11:35.926 +0300 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to host_dest=127.0.0.1 inside output group default-autolb-group from host_src=Nextcloud has been blocked for blocked_seconds=10700. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data. 07-17-2020 16:13:15.942 +0300 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to host_dest=127.0.0.1 inside output group default-autolb-group from host_src=Nextcloud has been blocked for blocked_seconds=10800. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data. 07-17-2020 16:14:04.615 +0300 INFO TcpOutputProc - Removing quarantine from idx=127.0.0.1:9997 07-17-2020 16:14:04.616 +0300 WARN TcpOutputFd - Connect to 127.0.0.1:9997 failed. Connection refused 07-17-2020 16:14:04.616 +0300 ERROR TcpOutputFd - Connection to host=127.0.0.1:9997 failed 07-17-2020 16:14:04.616 +0300 WARN TcpOutputFd - Connect to 127.0.0.1:9997 failed. Connection refused 07-17-2020 16:14:04.616 +0300 ERROR TcpOutputFd - Connection to host=127.0.0.1:9997 failed 07-17-2020 16:14:04.616 +0300 WARN TcpOutputProc - Applying quarantine to ip=127.0.0.1 port=9997 _numberOfFailures=2 (END)
... View more