Hello! I have an environment with about 200 machines, all Windows Servers. All servers are sending TCP information through port 9997 directly to my Heavy Forwarder, all information is allocated in the "Windows" index
What happens is that about 1-2x a day, the logs sent by Universal Forwarders stop from all machines leaving the Windows index blank. All other data that do not arrive through TCP 9997 are normal, such as some scripts that bring other types of information and save in other indexes.
The problem is only solved when Splunk is restarted in Heavy Forwarder
Trying to diagnose the problem, the only thing I could find is this message on all servers with Universal Forwarder installed
02-16-2022 15:20:51.293 -0400 WARN TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been blocked for 82200 seconds Has anyone gone through something similar, or can help me try to identify what is happening? Remembering that the Log in Heavy Forwader, doesn't bring me anything relevant Thanks in advance!
... View more