<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk eNcore not receiving any Data in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383461#M46636</link>
    <description>&lt;P&gt;I am experiencing the same issue. The 3.5 version will retrieve a burst of events but then stop. Every time I restart the estreamer processes, either from the Splunk UI by enabling/disabling eNcore, or from the shell using kill -HUP on the estreamer processes, or by restarting splunk entirely, I always get a burst of events when eNcore starts but then it will stop. I can wait hours and still not get a new event until I restart. Then I will get a burst of events from the last "bookmark".  I've tried changing many of the values in estreamer.conf including connectTimeout, responseTimeout, workerProcesses, with no luck. I am running on a server with 16 CPUs and 64GB RAM so have plenty of power. estreamer events get processed just fine with the old 2.2.1 version of the estreamer app/addon. &lt;/P&gt;</description>
    <pubDate>Thu, 26 Jul 2018 17:30:13 GMT</pubDate>
    <dc:creator>xtrjx</dc:creator>
    <dc:date>2018-07-26T17:30:13Z</dc:date>
    <item>
      <title>Why is Splunk eNcore not receiving any Data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383458#M46633</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Currently we noticed that splunk eNcore not receiving any Data, the error log on cisco:estreamer:log said &lt;STRONG&gt;ERROR EncoreException: PID file already exists&lt;/STRONG&gt;. So we assumed that there is conflicted eNcore process, so we try to &lt;EM&gt;./splencore.sh status&lt;/EM&gt; but found other error said &lt;STRONG&gt;"/etc/apps/TA-eStreamer/bin/encore/" does not exist&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;After searching for any info, we thought that there is problem with the pkc12 file, so we generated new file from FMC and put the new one into /TA-eStreamer/bin/encore and put the password from setup Page. Unfortunately while we try to save this configuration, another error occurred that said &lt;STRONG&gt;Encountered the following error while trying to update: Splunkd daemon is not responding: (u"Error connecting to /servicesNS/nobody/TA-eStreamer/apps/local/TA-eStreamer/setup: ('The read operation timed out',)",)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Any idea how to fix this?&lt;/P&gt;
&lt;P&gt;Thank you for all your assistance.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5196i09BBBCE3BA3BFCA2/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 15:00:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383458#M46633</guid>
      <dc:creator>fwbagusf</dc:creator>
      <dc:date>2022-09-26T15:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk eNcore not receiving any Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383459#M46634</link>
      <description>&lt;P&gt;Same boat here. Same message runs all day now. estreamer shows as running in the Cisco Security plugin, but no logs, alerts, results... Nothing.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 12:09:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383459#M46634</guid>
      <dc:creator>Blackburn2413</dc:creator>
      <dc:date>2018-06-20T12:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk eNcore not receiving any Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383460#M46635</link>
      <description>&lt;P&gt;I had to back out to the older version 3.0 and the events came back.  I don't know why, but the estreamer process will start, and I get a short burst of events, but stops and nothing happens from that point on.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 14:35:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383460#M46635</guid>
      <dc:creator>mhessel</dc:creator>
      <dc:date>2018-07-26T14:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk eNcore not receiving any Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383461#M46636</link>
      <description>&lt;P&gt;I am experiencing the same issue. The 3.5 version will retrieve a burst of events but then stop. Every time I restart the estreamer processes, either from the Splunk UI by enabling/disabling eNcore, or from the shell using kill -HUP on the estreamer processes, or by restarting splunk entirely, I always get a burst of events when eNcore starts but then it will stop. I can wait hours and still not get a new event until I restart. Then I will get a burst of events from the last "bookmark".  I've tried changing many of the values in estreamer.conf including connectTimeout, responseTimeout, workerProcesses, with no luck. I am running on a server with 16 CPUs and 64GB RAM so have plenty of power. estreamer events get processed just fine with the old 2.2.1 version of the estreamer app/addon. &lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 17:30:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383461#M46636</guid>
      <dc:creator>xtrjx</dc:creator>
      <dc:date>2018-07-26T17:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk eNcore not receiving any Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383462#M46637</link>
      <description>&lt;P&gt;Additional details: I enabled DEBUG estreamer logging. Now I noticed the following log messages estreamer.log that correspond with the data flow stopping:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2018-07-28 06:07:29,722 Decorator    DEBUG    Stashing sequence 80874; buffer: 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Those messages will repeat with the stashing sequence incrementing by about 100 at a time and buffer number incrementing from 1 to n until I restart the estreamer processes. For example, this is the last log entry after letting estreamer run all weekend:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2018-07-30 15:36:41,905 Decorator    DEBUG    Stashing sequence 167072; buffer: 857
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 30 Jul 2018 15:44:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383462#M46637</guid>
      <dc:creator>xtrjx</dc:creator>
      <dc:date>2018-07-30T15:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk eNcore not receiving any Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383463#M46638</link>
      <description>&lt;P&gt;This might be related to a bug on the FMC, where the estreamer service will peg a cpu at 100 percent if FireAMP or File events are enabled. Cisco tracks this as bug #CSCvj07843&lt;/P&gt;

&lt;P&gt;I was able to get this working by disabling the event types in the FMC, only allowing intrusion and malware events, and now I am getting events in splunk, but that is still running 30 minutes to an hour behind.  This does not seem to be related to the estreamer usage on the splunk/client side, but on the FMC instead.&lt;/P&gt;

&lt;P&gt;I'm guessing with the additional protocol support added in 3.5.0, the estreamer service on the server side is slowing down too much.&lt;/P&gt;

&lt;P&gt;From the bug report, fixed versions of the FMC are 6.2.2.4, and 6.2.3.2.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 17:01:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383463#M46638</guid>
      <dc:creator>mhessel</dc:creator>
      <dc:date>2018-08-02T17:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk eNcore not receiving any Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383464#M46639</link>
      <description>&lt;P&gt;Anything recent on this issue? I just discovered I am having the same. Just digging in now. Thanks for posting and your comments.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 14:02:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383464#M46639</guid>
      <dc:creator>Mesa_Splunkr</dc:creator>
      <dc:date>2019-09-24T14:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk eNcore not receiving any Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383465#M46640</link>
      <description>&lt;P&gt;I would take a look within $SPLUNK_HOME/etc/apps/TA-eStreamer/bin/encore. Should have a file referencing the FMC you had configured to reach out to. Mine was IP-port_proc.pid. Rename or delete that file. Restart Splunk. I began ingesting immediately following the restart.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:29:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383465#M46640</guid>
      <dc:creator>jbrinkman</dc:creator>
      <dc:date>2020-09-30T03:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk eNcore not receiving any Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383466#M46641</link>
      <description>&lt;P&gt;same issue for me with the last app release 3.6.8 &lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/3662/"&gt;https://splunkbase.splunk.com/app/3662/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;and FMC v6.4.0.7&lt;/P&gt;

&lt;P&gt;I received some data events during a few minutes and then the estreamer process goes down (and looping for a while)&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 10:04:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/383466#M46641</guid>
      <dc:creator>vinz2020</dc:creator>
      <dc:date>2020-03-10T10:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk eNcore not receiving any Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/511500#M62699</link>
      <description>&lt;P&gt;Per the deployment guide we have three options: &lt;A href="https://urldefense.com/v3/__https:/www.cisco.com/c/en/us/td/docs/security/firepower/630/api/eStreamer_enCore/eStreamereNcoreSplunkOperationsGuide_354.html*_Toc529958496__;Iw!!HO_ibWoPMs2OkA!fkRbQAk4C98DNl9-_sQgXMk0pvlvzmqWqmd7dkEiRAkMMqg5XMjv6tcgv-lRaGRHp28$" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/630/api/eStreamer_enCore/eStreamereNcoreSplunkOperationsGuide_354.html#_Toc529958496&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;■&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;0: Send all events from the earliest point available on the Firepower Management Center&lt;/P&gt;&lt;P&gt;■&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;1: Send all events that occur after receiving the client request&lt;/P&gt;&lt;P&gt;■&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2: Use a bookmark to pick up where we left off. First run is from 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, first modify the file to use option 0. Restart the encore and leave it running some time and verify if you see events.&lt;/P&gt;&lt;P&gt;After that you can modify the file to option 1 and restart the encore again and verify if events are seen in encore.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 11:39:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/511500#M62699</guid>
      <dc:creator>mkemp</dc:creator>
      <dc:date>2020-07-29T11:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk eNcore not receiving any Data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/614444#M77682</link>
      <description>&lt;P&gt;This resolved my issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Sep 2022 08:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-eNcore-not-receiving-any-Data/m-p/614444#M77682</guid>
      <dc:creator>shahrukhvp</dc:creator>
      <dc:date>2022-09-25T08:01:34Z</dc:date>
    </item>
  </channel>
</rss>

