Click here to view the original link.
Trying to setup a brand new Windows 11 Splunk UF and point it at Cribl.Cloud Splunk TCP /w TLS, no client auth. Using the default cribl provided TLS certificates on the endpoint, following the directions at https://docs.cribl.io/stream/sources-splunk/#config-splunk-fwd but the UF won't connect, it repeats the following continously:
06-02-2026 16:00:49.883 -0500 ERROR TcpOutputFd [4296 TcpOutEloop] - Invalid payload_size=352518912 received while in parseState=1
06-02-2026 16:00:49.883 -0500 WARN AutoLoadBalancedConnectionStrategy [4296 TcpOutEloop] - Applying quarantine to ip=100.20.132.14 port=9997 connid=2 _numberOfFailures=2