<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk HEC - AWS VPC Flow Logs - Timeout in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-HEC-AWS-VPC-Flow-Logs-Timeout/m-p/470335#M57799</link>
    <description>&lt;P&gt;One of the alternatives to ingest AWS VPC Flow Logs into Splunk is with NetFlow Optimizer (NFO). There are additional benefits that can be achieved by using NFO: data consolidation and enrichment (EC2 instances names, regions, etc.) &lt;/P&gt;

&lt;P&gt;Here is the link to learn more &lt;A href="https://bit.ly/2w5Pa5L"&gt;https://bit.ly/2w5Pa5L&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Should you have any questions, please don’t hesitate to reach out and we’ll be happy to help you.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Apr 2020 19:01:41 GMT</pubDate>
    <dc:creator>NetFlow_Logic</dc:creator>
    <dc:date>2020-04-01T19:01:41Z</dc:date>
    <item>
      <title>Splunk HEC - AWS VPC Flow Logs - Timeout</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-HEC-AWS-VPC-Flow-Logs-Timeout/m-p/470333#M57797</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've been trying, unsuccessfully, to configure a Splunk HEC endpoint to consume AWS VPC Flow Logs via Firehose. &lt;/P&gt;

&lt;P&gt;Having slowly worked through various errors, including HEC acknowledgement being disabled, SSL certificates issues, I thought I had beaten the last of them.  However, I am now getting a rather unhelpful error in my Firehose failed events log as follows:&lt;/P&gt;

&lt;P&gt;"attemptsMade":34,"arrivalTimestamp":1567429559545,"errorCode":"Splunk.ConnectionTimeout","errorMessage":"The connection to Splunk timed out. This might be a transient error and the request will be retried. Kinesis Firehose backs up the data to Amazon S3 if all retries fail."&lt;/P&gt;

&lt;P&gt;Having had previous errors stating that the HEC indexer acknowledgement was disabled, and that ELB stickiness was not enabled, I'm fairly certain I am getting traffic to and from my Splunk instances. So I am not sure now why this is timing out. Is there any way to understand what is causing this? HEC Acknowledgement timeout is set to 600 seconds, so I don't believe it is this (plus that has its own error and corresponding code). &lt;/P&gt;

&lt;P&gt;Any help gratefully received as I've been through all the documentation I can find, and am now stumped!&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2019 14:28:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-HEC-AWS-VPC-Flow-Logs-Timeout/m-p/470333#M57797</guid>
      <dc:creator>andycohen</dc:creator>
      <dc:date>2019-09-02T14:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk HEC - AWS VPC Flow Logs - Timeout</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-HEC-AWS-VPC-Flow-Logs-Timeout/m-p/470334#M57798</link>
      <description>&lt;P&gt;I built an app to help troubleshoot firehose issues : &lt;A href="https://github.com/amiracle/kinesis_data_firehose_helper" target="_blank"&gt;https://github.com/amiracle/kinesis_data_firehose_helper&lt;/A&gt; (It will be on splunkbase soon once it gets vetted.) You can use this to help troubleshoot some of the issues and make sure your setup is correct and able to send data into HEC. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:48:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-HEC-AWS-VPC-Flow-Logs-Timeout/m-p/470334#M57798</guid>
      <dc:creator>amiracle</dc:creator>
      <dc:date>2020-09-30T04:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk HEC - AWS VPC Flow Logs - Timeout</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-HEC-AWS-VPC-Flow-Logs-Timeout/m-p/470335#M57799</link>
      <description>&lt;P&gt;One of the alternatives to ingest AWS VPC Flow Logs into Splunk is with NetFlow Optimizer (NFO). There are additional benefits that can be achieved by using NFO: data consolidation and enrichment (EC2 instances names, regions, etc.) &lt;/P&gt;

&lt;P&gt;Here is the link to learn more &lt;A href="https://bit.ly/2w5Pa5L"&gt;https://bit.ly/2w5Pa5L&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Should you have any questions, please don’t hesitate to reach out and we’ll be happy to help you.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 19:01:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-HEC-AWS-VPC-Flow-Logs-Timeout/m-p/470335#M57799</guid>
      <dc:creator>NetFlow_Logic</dc:creator>
      <dc:date>2020-04-01T19:01:41Z</dc:date>
    </item>
  </channel>
</rss>

