Deployment Architecture

Splunk indexing is not working

manjunathaya
New Member

Team,

Geeting below error while indexing. Please let me know how can we fix this?

11-25-2019 07:39:35.796 -0500 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to host_dest=vc2crtp1428667np.fmr.com inside output group rtpindexer from host_src=vc2coma2429304n.fmr.com has been blocked
for blocked_seconds=600. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.

Tags (1)
0 Karma

oscar84x
Contributor

Do you have any forwarders working successfully, so that you can compare configurations?
What does your outputs and inputs look like?
Is the Indexer(s) expecting SSL?
Could also be a network issue, is the port open on the receiving end?

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...