<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Cisco Sourcefire: Why is the wrong year extracted from events? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-Sourcefire-Why-is-the-wrong-year/m-p/127097#M10124</link>
    <description>&lt;P&gt;I have the exact same issue with cisco sourcefire logs where splunk assumes a random year on the timestamp.&lt;BR /&gt;
There is no year information in the logs.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Nov 2019 19:16:11 GMT</pubDate>
    <dc:creator>jaivijay_rio</dc:creator>
    <dc:date>2019-11-22T19:16:11Z</dc:date>
    <item>
      <title>Splunk Add-on for Cisco Sourcefire: Why is the wrong year extracted from events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-Sourcefire-Why-is-the-wrong-year/m-p/127094#M10121</link>
      <description>&lt;P&gt;I am currently investigating issue where "_time" has year extracted from last octet from the syslog source IP. The logs are from sourcefire and sending syslog without year. &lt;/P&gt;

&lt;P&gt;the raw syslog from two source  DCs &lt;/P&gt;

&lt;P&gt;Feb 4 10:52:22 SIGIPSDC01 ipsdetect00: [119:31:1] http_inspect: UNKNOWN METHOD [Impact: Currently Not Vulnerable] From "SIG-IPS-DE-01/SIGIPS3D01" at Wed Feb 4 10:52:21 2015 UTC [Classification: Unknown Traffic] [Priority: 3] {tcp} 203.19.222.5:26118-&amp;gt;23.23.154.127:80&lt;/P&gt;

&lt;P&gt;Feb 4 10:50:51 SIGIPSDC02 ipsdetect00: [119:31:1] http_inspect: UNKNOWN METHOD [Impact: Currently Not Vulnerable] From "SIG-IPS-DE-01/SIGIPS3D01" at Wed Feb 4 10:50:51 2015 UTC [Classification: Unknown Traffic] [Priority: 3] {tcp} 203.19.222.5:26118-&amp;gt;23.23.154.127:80&lt;/P&gt;

&lt;P&gt;These logs are forwarded by heavy forwarder and actual logs from search head looks like:&lt;/P&gt;

&lt;P&gt;_time&lt;BR /&gt;
&lt;EM&gt;2/4/14 9:50:51.000 PM&lt;/EM&gt;   &lt;STRONG&gt;Feb 4 21:50:51 10.0.12.14&lt;/STRONG&gt;Feb 4 10:50:51 SIGIPSDC02 ipsdetect00: [119:31:1] http_inspect: UNKNOWN METHOD [Impact: Currently Not Vulnerable] From "SIG-IPS-DE-01/SIGIPS3D01" at Wed Feb 4 10:50:51 2015 UTC [Classification: Unknown Traffic] [Priority: 3] {tcp} 203.19.222.5:26118-&amp;gt;23.23.154.127:80&lt;/P&gt;

&lt;P&gt;_time&lt;BR /&gt;
 &lt;EM&gt;2/4/13  9:52:22.000 PM&lt;/EM&gt; &lt;STRONG&gt;Feb 4 21:52:22 10.0.12.13&lt;/STRONG&gt; Feb 4 10:52:22 SIGIPSDC01 ipsdetect00: [119:31:1] http_inspect: UNKNOWN METHOD [Impact: Currently Not Vulnerable] From "SIG-IPS-DE-01/SIGIPS3D01" at Wed Feb 4 10:52:21 2015 UTC [Classification: Unknown Traffic] [Priority: 3] {tcp} 203.19.222.5:26118-&amp;gt;23.23.154.127:80&lt;/P&gt;

&lt;P&gt;This issue occurs only if last octet of source syslog device ends with .10 or .11 or .12 or .13 or .14 or .15&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:50:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-Sourcefire-Why-is-the-wrong-year/m-p/127094#M10121</guid>
      <dc:creator>ramsanga</dc:creator>
      <dc:date>2020-09-28T18:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco Sourcefire: Why is the wrong year extracted from events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-Sourcefire-Why-is-the-wrong-year/m-p/127095#M10122</link>
      <description>&lt;P&gt;We've filed a bug for this and will address.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Feb 2015 01:58:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-Sourcefire-Why-is-the-wrong-year/m-p/127095#M10122</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-02-22T01:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco Sourcefire: Why is the wrong year extracted from events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-Sourcefire-Why-is-the-wrong-year/m-p/127096#M10123</link>
      <description>&lt;P&gt;following up... this was discovered to be a Splunk configuration issue that we can't address well from within the Add-on, so we've updated the documentation: &lt;A href="http://docs.splunk.com/Documentation/AddOns/latest/Sourcefire/Troubleshooting#Data_truncation_issues"&gt;http://docs.splunk.com/Documentation/AddOns/latest/Sourcefire/Troubleshooting#Data_truncation_issues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2015 17:56:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-Sourcefire-Why-is-the-wrong-year/m-p/127096#M10123</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-03-01T17:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco Sourcefire: Why is the wrong year extracted from events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-Sourcefire-Why-is-the-wrong-year/m-p/127097#M10124</link>
      <description>&lt;P&gt;I have the exact same issue with cisco sourcefire logs where splunk assumes a random year on the timestamp.&lt;BR /&gt;
There is no year information in the logs.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 19:16:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-Sourcefire-Why-is-the-wrong-year/m-p/127097#M10124</guid>
      <dc:creator>jaivijay_rio</dc:creator>
      <dc:date>2019-11-22T19:16:11Z</dc:date>
    </item>
  </channel>
</rss>

