Splunk on this host(s) is configured to forward its data to "local_55153" which is defined in outputs.conf:
Forwarding to output group local_55153 has been blocked for 1550 seconds.
If it is unable to connect to that output group, the data will begin to queue and once the queues are filled it will no longer process/ingest new data. You will want to review ouputs.conf on these hosts and determine if the settings are correct. If they are, then you will want to ensure that the instances that make up "local_55153" are reachable, are listening on the relevant port and are able to accept data.
... View more