@harsmarvania57 I am receving that exact message on my Splunk Heavy forwarder. Here is the breakdown of my environment: 1. Splunk Deployer 3. Search Head Cluster 3 Splunk Indexers 1. Master Cluster 1 Deployment/Licence server I notice data stopped coming in about 5 days ago. However, I am receiving this message on the HF: TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to host_dest= inside output group default-autolb-group from host_src=heavy-forwarder.example.com has been blocked for blocked_seconds=1440. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data. Receiving port : 9997 is enabled on Splunk HF Dashboard but port 9997 is NOT LISTEN on the HF command line I would appreciate any help to resolve this issue as soon as possible.
... View more