<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1 in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/559405#M66090</link>
    <description>&lt;P&gt;I am on 6.4.2 and I just had to edit the clean statement to find the events (and I didn't customize the location). I've been scratching my head thinking I must have missed a variable somewhere but then I came across this post... what is going on?...&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jul 2021 12:22:28 GMT</pubDate>
    <dc:creator>_joe</dc:creator>
    <dc:date>2021-07-14T12:22:28Z</dc:date>
    <item>
      <title>Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1- Why am I not receiving any results?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/531454#M64323</link>
      <description>&lt;P&gt;I'm running splunk 8.1.0.1 and Cisco eStreamer eNcore 4.0.9 and configured cisco FMC for estream integration but it doent show any logs. I have some Errors in splunkd.log and estreamer.log.&lt;/P&gt;
&lt;P&gt;I dont&amp;nbsp; receive any result when I search for&lt;/P&gt;
&lt;P&gt;sourcetype="cisco:estreamer:data"&lt;/P&gt;
&lt;P&gt;splunkd.log:&lt;/P&gt;
&lt;P&gt;12-01-2020 10:55:45.104 +0330 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/_telemetry/db duration=0.000&lt;BR /&gt;12-01-2020 10:56:16.088 +0330 WARN LocalAppsAdminHandler - Using deprecated capabilities for write: admin_all_objects or edit_local_apps. See enable_install_apps in limits.conf&lt;BR /&gt;12-01-2020 10:56:35.888 +0330 WARN CalcFieldProcessor - Invalid eval expression for 'EVAL-first_pkt_sec' in stanza [cisco:estreamer:data]: The expression is malformed. Expected AND.&lt;BR /&gt;12-01-2020 10:56:43.574 +0330 WARN CalcFieldProcessor - Invalid eval expression for 'EVAL-first_pkt_sec' in stanza [cisco:estreamer:data]: The expression is malformed. Expected AND.&lt;BR /&gt;12-01-2020 11:00:00.002 +0330 INFO ExecProcessor - setting reschedule_ms=3599998, for command=/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_instrumentation/bin/instrumentation.py&lt;BR /&gt;12-01-2020 11:00:45.541 +0330 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/TA-eStreamer/bin/splencore.sh clean" find: ‘../../data’: No such file or directory&lt;BR /&gt;12-01-2020 11:04:45.710 +0330 WARN LocalAppsAdminHandler - Using deprecated capabilities for write: admin_all_objects or edit_local_apps. See enable_install_apps in limits.conf&lt;BR /&gt;12-01-2020 11:09:16.851 +0330 WARN CalcFieldProcessor - Invalid eval expression for 'EVAL-first_pkt_sec' in stanza [cisco:estreamer:data]: The expression is malformed. Expected AND.&lt;BR /&gt;12-01-2020 11:09:47.042 +0330 WARN CalcFieldProcessor - Invalid eval expression for 'EVAL-first_pkt_sec' in stanza [cisco:estreamer:data]: The expression is malformed. Expected AND.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;estreamer.log&lt;/P&gt;
&lt;P&gt;2020-12-01 10:57:47,097 Service ERROR [no message or attrs]: PID file already exists&lt;BR /&gt;2020-12-01 10:58:58,905 Monitor INFO Running. 3465700 handled; average rate 1604.32 ev/sec;&lt;BR /&gt;2020-12-01 10:59:47,105 Service ERROR [no message or attrs]: PID file already exists&lt;BR /&gt;2020-12-01 11:00:58,856 Monitor INFO Running. 3642600 handled; average rate 1597.5 ev/sec;&lt;BR /&gt;2020-12-01 11:01:47,003 Service ERROR [no message or attrs]: PID file already exists&lt;BR /&gt;2020-12-01 11:02:59,543 Monitor INFO Running. 3729700 handled; average rate 1553.92 ev/sec;&lt;BR /&gt;2020-12-01 11:03:46,998 Service ERROR [no message or attrs]: PID file already exists&lt;BR /&gt;2020-12-01 11:04:59,259 Monitor INFO Running. 3744100 handled; average rate 1485.59 ev/sec;&lt;BR /&gt;2020-12-01 11:05:47,086 Service ERROR [no message or attrs]: PID file already exists&lt;BR /&gt;2020-12-01 11:06:59,648 Monitor INFO Running. 3759600 handled; average rate 1423.95 ev/sec;&lt;BR /&gt;2020-12-01 11:07:47,049 Service ERROR [no message or attrs]: PID file already exists&lt;BR /&gt;2020-12-01 11:08:59,299 Monitor INFO Running. 3773900 handled; average rate 1367.29 ev/sec;&lt;BR /&gt;2020-12-01 11:09:47,126 Service ERROR [no message or attrs]: PID file already exists&lt;BR /&gt;2020-12-01 11:10:59,220 Monitor INFO Running. 3788200 handled; average rate 1315.21 ev/sec;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.gif" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12127i56EDE63C2C192BFC/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.gif" alt="4.gif" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.gif" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12126i8FD780D52B9F3C6D/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.gif" alt="3.gif" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.gif" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12128iEBBF40E41C733E98/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.gif" alt="2.gif" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.gif" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12125iB733D89A30500C56/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.gif" alt="1.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 21:51:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/531454#M64323</guid>
      <dc:creator>alcman</dc:creator>
      <dc:date>2022-06-03T21:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/531478#M64324</link>
      <description>&lt;P&gt;I have the exact same issue, what helps is removing the pid file that exists in the following location:&lt;BR /&gt;$SPLUNK_HOME/etc/apps/TA-eStreamer/bin/encore&lt;BR /&gt;&lt;BR /&gt;Then restart Splunk.&lt;BR /&gt;&lt;BR /&gt;I have noticed that the issue returns after Splunk has been rebooted. I was about to start a thread on this subject.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 09:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/531478#M64324</guid>
      <dc:creator>fwijnholds_splu</dc:creator>
      <dc:date>2020-12-01T09:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/531502#M64330</link>
      <description>&lt;P&gt;thank you for your reply. this error "Service ERROR [no message or attrs]: PID file already exists"&amp;nbsp; resolved.&lt;/P&gt;&lt;P&gt;estreamer.log.&lt;/P&gt;&lt;P&gt;2020-12-01 15:00:59,454 Monitor INFO Running. 5325800 handled; average rate 319.29 ev/sec;&lt;BR /&gt;2020-12-01 15:02:00,726 Monitor INFO Running. 10800 handled; average rate 89.8 ev/sec;&lt;BR /&gt;2020-12-01 15:02:58,762 Monitor INFO Running. 5336200 handled; average rate 317.63 ev/sec;&lt;BR /&gt;2020-12-01 15:04:00,887 Monitor INFO Running. 21000 handled; average rate 87.4 ev/sec;&lt;BR /&gt;2020-12-01 15:04:59,552 Monitor INFO Running. 5345600 handled; average rate 315.93 ev/sec;&lt;BR /&gt;2020-12-01 15:06:00,267 Monitor INFO Running. 29500 handled; average rate 81.91 ev/sec;&lt;BR /&gt;2020-12-01 15:06:58,891 Monitor INFO Running. 5354100 handled; average rate 314.2 ev/sec;&lt;BR /&gt;2020-12-01 15:08:00,234 Monitor INFO Running. 39200 handled; average rate 81.62 ev/sec;&lt;BR /&gt;2020-12-01 15:08:59,062 Monitor INFO Running. 5364000 handled; average rate 312.58 ev/sec;&lt;BR /&gt;2020-12-01 15:10:00,882 Monitor INFO Running. 50400 handled; average rate 83.97 ev/sec;&lt;BR /&gt;2020-12-01 15:10:59,381 Monitor INFO Running. 5377100 handled; average rate 311.17 ev/sec;&lt;BR /&gt;2020-12-01 15:12:00,891 Monitor INFO Running. 63200 handled; average rate 87.76 ev/sec;&lt;BR /&gt;2020-12-01 15:12:58,983 Monitor INFO Running. 5388800 handled; average rate 309.7 ev/sec;&lt;BR /&gt;2020-12-01 15:13:59,918 Monitor INFO Running. 73300 handled; average rate 87.25 ev/sec;&lt;/P&gt;&lt;P&gt;but these errors persist in splunkd.log and there is nothing related to cisco:estreamer:data:&lt;/P&gt;&lt;P&gt;12-01-2020 15:02:04.720 +0330 WARN CalcFieldProcessor - Invalid eval expression for 'EVAL-first_pkt_sec' in stanza [cisco:estreamer:data]: The expression is malformed. Expected AND.&lt;BR /&gt;12-01-2020 15:02:17.575 +0330 WARN CalcFieldProcessor - Invalid eval expression for 'EVAL-first_pkt_sec' in stanza [cisco:estreamer:data]: The expression is malformed. Expected AND.&lt;BR /&gt;12-01-2020 15:09:14.101 +0330 WARN LocalAppsAdminHandler - Using deprecated capabilities for write: admin_all_objects or edit_local_apps. See enable_install_apps in limits.conf&lt;BR /&gt;12-01-2020 15:09:16.724 +0330 WARN LocalAppsAdminHandler - Using deprecated capabilities for write: admin_all_objects or edit_local_apps. See enable_install_apps in limits.conf&lt;BR /&gt;12-01-2020 15:09:57.608 +0330 WARN TelemetryMetricHandler - Could not retrieve CDS URL from quickdraw.&lt;BR /&gt;12-01-2020 15:14:58.055 +0330 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/TA-eStreamer/bin/splencore.sh clean" find: ‘../../data’: No such file or directory&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.gif" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12135i82EBF1FD14CFAB1E/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.gif" alt="5.gif" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 11:51:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/531502#M64330</guid>
      <dc:creator>alcman</dc:creator>
      <dc:date>2020-12-01T11:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/531785#M64354</link>
      <description>&lt;P&gt;Check the following things on the CLI:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/etc/apps/TA-eStreamer/bin/splencore.sh test&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;should produce this message as the last line:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2020-12-02 22:27:20,963 Diagnostics INFO Connection successful&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If it is success-full, check this command, if not skip to the next bit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/etc/apps/TA-eStreamer/bin/splencore.sh status&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It should say:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;status_id=1 status="Running"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If these things check out, but you still have errors, n&lt;SPAN&gt;avigate to the TA-eStreamer bin directory, located in $SPLUNK_HOME/etc/apps/TA-eStreamer/bin.&amp;nbsp; Open the&amp;nbsp;splencore.sh with your favorite editor, look at the following and make sure it reflects your path:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;#This is commented out by default, pleaes set this to the home
#directory of your Splunk Heavy Forwarder

SPLUNK_HOME=/opt/splunk

#This may be needed for CentOS, run this outside of the shell
LD_LIBRARY_PATH=/opt/splunk/lib&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;That got rid of the error messages. I did come from an upgrade. I decided to get rid of this deployment and followed these steps:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/670/api/eStreamer_enCore/eStreamereNcoreSplunkOperationsGuide_409.html#_Toc529958489" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/670/api/eStreamer_enCore/eStreamereNcoreSplunkOperationsGuide_409.html#_Toc529958489&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I did find this in the inputs; the TA is looking for data to be written to:&amp;nbsp;$SPLUNK_HOME/etc/apps/TA-eStreamer/data in the inputs.conf&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# Where data is written to
[monitor://$SPLUNK_HOME/etc/apps/TA-eStreamer/data]
disabled = 0
source = encore
sourcetype = cisco:estreamer:data
crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This directory does not exist. Instead the files are written to:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/etc/apps/TA-eStreamer/bin/encore/data/splunk&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 00:13:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/531785#M64354</guid>
      <dc:creator>fwijnholds_splu</dc:creator>
      <dc:date>2020-12-03T00:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/531891#M64366</link>
      <description>Crazy. I had these same symptoms, and I just discovered the problem with the log path today. I was going to post this same information but you beat me to it by a day.&lt;BR /&gt;&lt;BR /&gt;I have a TAC case open with Cisco and I'm trying to get put in touch with the developers of the TA so I can communicate the problem to them, and hopefully get them to update either the logging path in the python code or the monitor stanza in inputs.conf.</description>
      <pubDate>Thu, 03 Dec 2020 16:55:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/531891#M64366</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2020-12-03T16:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/532090#M64378</link>
      <description>&lt;P&gt;Another quick update. A bug was filed on the issue on 11/20/2020, &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvw51040" target="_self"&gt;CSCvw51040&lt;/A&gt;. So Cisco is aware and they are working on it.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Dec 2020 16:43:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/532090#M64378</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2020-12-05T16:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/534954#M64555</link>
      <description>&lt;P&gt;I discovered a second bug with v4.0.9 of the addon. It worked for a few days, then suddenly it stopped. I found these errors in the estreamer.log file:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2020-12-17 13:46:17,854 Monitor      ERROR    [no message or attrs]: ProxyProcess[name=subscriberParser].request(status) timeout
2020-12-17 13:48:17,992 Monitor      ERROR    [no message or attrs]: ProxyProcess[name=subscriberParser].request(status) timeout
2020-12-17 13:50:17,883 Monitor      ERROR    [no message or attrs]: ProxyProcess[name=subscriberParser].request(status) timeout
2020-12-17 13:52:17,775 Monitor      ERROR    [no message or attrs]: ProxyProcess[name=subscriberParser].request(status) timeout
2020-12-17 13:54:17,910 Monitor      ERROR    [no message or attrs]: ProxyProcess[name=subscriberParser].request(status) timeout
2020-12-17 13:56:17,806 Monitor      ERROR    [no message or attrs]: ProxyProcess[name=subscriberParser].request(status) timeout&lt;/LI-CODE&gt;&lt;P&gt;I tried restarting the addon and splunk multiple times but could never recover the connection. I opened a support case was advised of bug &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvw88449" target="_self"&gt;CSCvw88449&lt;/A&gt;&amp;nbsp;that also affects 4.0.9.&lt;/P&gt;&lt;P&gt;There are too many issues in 4.0.9 for me, so I decided to roll back to the latest 3.x version (3.7.1) and run on that. It seems to be stable.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 13:51:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/534954#M64555</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2021-01-06T13:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/535055#M64565</link>
      <description>&lt;P&gt;Thanks for the update. Does 3.7 run on Splunk 8.1.1? I thought that did not have python 3 support yet.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 14:38:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/535055#M64565</guid>
      <dc:creator>fwijnholds_splu</dc:creator>
      <dc:date>2021-01-07T14:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/535057#M64566</link>
      <description>&lt;P&gt;I don't know if it runs on v8.1.1, I am running it on v8.0.5. But I have configured 8.0.5 to run python3 by default in &lt;STRONG&gt;etc/system/local/server.conf&lt;/STRONG&gt; and the TA automation seems to run fine.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 14:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/535057#M64566</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2021-01-07T14:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/535072#M64568</link>
      <description>&lt;P&gt;I emailed &lt;A href="mailto:encore-community@cisco.com" target="_blank"&gt;encore-community@cisco.com&lt;/A&gt;&amp;nbsp;notifying them on 12/10, as well as to change the splencore.sh to reflect the correct path for cleaning. They said they would fix on the next upgrade.&lt;/P&gt;&lt;P&gt;I also noticed there are other issues such as the knowledge bundle sizes that are being created. I think it's best to roll back for now until they fix all other issues.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 16:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/535072#M64568</guid>
      <dc:creator>rsanders30</dc:creator>
      <dc:date>2021-01-07T16:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/535196#M64574</link>
      <description>&lt;P&gt;I'm curious about where you found that email address? Opening a TAC case and getting in touch with an engineer who knew what Splunk is was a challenge for me. I would definitely have tried your approach if I knew about that email address.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2021 14:08:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/535196#M64574</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2021-01-08T14:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/535212#M64578</link>
      <description>&lt;P&gt;I had it from a while ago. It was in their documentation from v3.5 under support. They probably prefer users to use TAC though.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/630/api/eStreamer_enCore/eStreamereNcoreCLIOperationsGuide_354.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/630/api/eStreamer_enCore/eStreamereNcoreCLIOperationsGuide_354.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2021 15:09:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/535212#M64578</guid>
      <dc:creator>rsanders30</dc:creator>
      <dc:date>2021-01-08T15:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/541332#M64963</link>
      <description>&lt;P&gt;Have you had any better luck with 4.0.11?&lt;/P&gt;&lt;P&gt;I had a lot of issues with 4.0.9 (back in Oct-Nov) but at a certain point I was hitting the following errors and&amp;nbsp; I couldn't ingest data so I had to downgrade.&amp;nbsp;&lt;/P&gt;&lt;P&gt;root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; INFO&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 'View' object has no attribute '_View__isHex'&lt;BR /&gt;Decorator&amp;nbsp;&amp;nbsp;&amp;nbsp; ERROR&amp;nbsp;&amp;nbsp;&amp;nbsp; [no message or attrs]: 'View' object has no attribute '_View__isHex'\n'View' object has no attribute '_View__isHex'Traceback (most recent call last):\n...............&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I am just noticing my issue seems different than yours but they related it to the same bug&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 12:44:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/541332#M64963</guid>
      <dc:creator>_joe</dc:creator>
      <dc:date>2021-02-25T12:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/541335#M64964</link>
      <description>I have not tried 4.0.11 yet.</description>
      <pubDate>Thu, 25 Feb 2021 13:21:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/541335#M64964</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2021-02-25T13:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/542061#M65012</link>
      <description>&lt;P&gt;I have become intimately familiar with the eStreamer TA over the last couple of years.&amp;nbsp; Let me see if I can help with some of these.&lt;/P&gt;&lt;P&gt;setup.xml was removed in v4.0.x, so the configuration that was previously done with two passes through setup.xml in the GUI or &lt;FONT face="lucida sans unicode,lucida sans" color="#666699"&gt;TA-eStreamer/local/encore.conf&lt;/FONT&gt; now has to be done by manually editing the &lt;FONT face="lucida sans unicode,lucida sans" color="#FF6600"&gt;TA-eStreamer/bin/encore/estreamer.conf&lt;/FONT&gt; file, which is not nearly as easy-peasy as using the GUI.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Packets, Connections, &amp;amp; Metadata &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;(not mentioned earlier - but seems worth noting since it could be a data hog and is completely left out of the new instructions)&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;In addition to manually enabling and setting the hosts in &lt;FONT face="lucida sans unicode,lucida sans" color="#FF6600"&gt;TA-eStreamer/bin/encore/estreamer.conf&lt;/FONT&gt;, you also have to manually enable/disable packets, connections, and metadata options that were previously available via checkboxes on the bottom of the setup page.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;packets are enabled by default - which could be problematic since packet data is quite large&lt;/LI&gt;&lt;LI&gt;these options are in the "records" section of estreamer.conf&lt;/LI&gt;&lt;LI&gt;as info, our previous configuration which had connections enabled, but packets and metadata disabled is below.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;"records": {
    "connections": true, 
    "core": true, 
    "excl@comment": [
	"These records will be excluded regardless of above (overrides 'include')", 
	"e.g. to exclude flow and IPS events use [ 71, 400 ]"
    ], 
    "exclude": [], 
    "inc@comment": "These records will be included regardless of above", 
    "include": [], 
    "intrusion": true, 
    "metadata": false, 
    "packets": false, 
    "rna": true, 
    "rua": true
}
}, &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Data Directory Change &lt;/STRONG&gt;(affects inputs.conf &amp;amp; clean() function of splencore.sh script)&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As noted above the data directory has changed to &lt;FONT face="lucida sans unicode,lucida sans" color="#FF6600"&gt;TA-eStreamer/bin/encore/data/splunk/&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The filename format has also changed from &lt;FONT face="lucida sans unicode,lucida sans" color="#0000FF"&gt;encore.EPOCHTIME.log&lt;/FONT&gt; to &lt;FONT face="lucida sans unicode,lucida sans" color="#0000FF"&gt;encore.logEPOCHTIME&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There are multiple ways you can address this.&amp;nbsp; Either change where the data lives or point everything to the new locale.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Change Where the Data Lives&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Update the "uri" in the "handler" section of&amp;nbsp;&lt;FONT face="lucida sans unicode,lucida sans" color="#FF6600"&gt;TA-eStreamer/bin/encore/estreamer.conf&amp;nbsp;&lt;/FONT&gt;back to the old value:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;"uri": "relfile:///../../data/encore.{0}.log"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Update Where the App Looks&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Add a new monitor stanza in&amp;nbsp;TA-eStreamer/local/inputs.conf for the new data path:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;[monitor://$SPLUNK_HOME/etc/apps/TA-eStreamer/bin/encore/data/splunk]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update the path in the clean() stanza of the &lt;FONT face="lucida sans unicode,lucida sans" color="#FF6600"&gt;TA-eStreamer/bin/splencore.sh &lt;/FONT&gt;script to the new data path:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;clean() {
    # Delete data older than 12 hours -&amp;gt; 720mins
    # find ../../data -type f -mmin +720 -delete
    # correcting path to new path in new version 4.0.11 of TA
    find $SPLUNK_HOME/etc/apps/TA-eStreamer/bin/encore/data/splunk -type f -mmin +720 -delete
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;first_pkt_sec EVAL Error&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The&amp;nbsp;EVAL statement triggering the error looks like it was a FIELDALIAS that someone switched over to an EVAL without actually switching it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The culprit:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;EVAL-first_pkt_sec = event_sec as first_pkt_sec​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The fancy EVAL we wrote to address this coalesces several time fields to ensure the 'first_pkt_sec' field gets populated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;EVAL-first_pkt_sec = coalesce(first_pkt_sec, connection_sec, event_sec)​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could also accomplish this with a simple eval that will override the EVAL triggering the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;EVAL-first_pkt_sec = event_sec ​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other Props Fixes&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We also noted that the search-time props had conflicting FIELDALIAS functions, no KV_MODE, and a few other things; so we added some additional&amp;nbsp;&lt;EM&gt;flare&amp;nbsp;&lt;/EM&gt;to address those issues. Just in case this might also be helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;[cisco:estreamer:data]
#### Setting the time format to epoch time (not set in TA)
TIME_FORMAT = %s

#### Setting KV_MODE ####
KV_MODE = auto

#### Splunk CIM - Intrusion Detection Fields ####
EVAL-severity = coalesce(severity, priority)
EVAL-signature = coalesce(case(signature="",null(),true(),signature), detection, msg)

#### Splunk CIM - Malware Fields ####
EVAL-url = coalesce(url, uri)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If it wasn't clear - the first_pkt_sec and "other props fixes" were all applied to&amp;nbsp;our &lt;FONT face="lucida sans unicode,lucida sans" color="#FF6600"&gt;TA-eStreamer/local/props.conf &lt;/FONT&gt;file.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 01:34:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/542061#M65012</guid>
      <dc:creator>gurlest</dc:creator>
      <dc:date>2021-03-03T01:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/542433#M65049</link>
      <description>&lt;P&gt;I found one more thing today when I was testing the v4.0.11 update.&amp;nbsp; I noticed that the estreamer.conf process wasn't stopping when I stopped splunk and that the .pid file wasn't getting deleted when splunk stopped either.&amp;nbsp; It was almost like the estreamer process wasn't dependent on the splunk service.&lt;/P&gt;&lt;P&gt;After running a diff command against the estreamer.conf from v3.6.8 and the new one for v4.0.11, I noticed that was exactly what happened.&amp;nbsp; The part of the script noting that it should be depending on splunk has been removed.&lt;/P&gt;&lt;P&gt;Adding lines 2-4 back to the &lt;FONT face="lucida sans unicode,lucida sans" color="#FF6600"&gt;TA-eStreamer/bin/encore/estreamer.conf&lt;/FONT&gt; file re-added the splunk service dependency.&lt;/P&gt;&lt;LI-CODE lang="python"&gt;{
    "conditions": [
        "splunk"
    ],&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 05 Mar 2021 01:30:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/542433#M65049</guid>
      <dc:creator>gurlest</dc:creator>
      <dc:date>2021-03-05T01:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/544821#M65203</link>
      <description>&lt;P&gt;Me again... While deploying this we noted that the TA-eStreamer/bin/encore/data/splunk directory being the data directory causes more problems than not.&lt;/P&gt;&lt;P&gt;The newest problem being that the /bin directory is replicated, so if the heavy-forwarder has any searchpeers, it will cause bundle replication issues because Splunk will be attempting to replicate 200gb+ data directory all over the place.&lt;/P&gt;&lt;P&gt;We have opted to move the data directory back to the old location of TA-eStreamer/data in the TA--eStreamer/bin/encore/estreamer.conf file.&amp;nbsp; This addresses the issues with:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;/bin/splencore.sh clean() location being incorrect&lt;/LI&gt;&lt;LI&gt;/default/inputs.conf monitor location for data files being incorrect&lt;/LI&gt;&lt;LI&gt;/bin/encore/data/splunk being 200gb+ causes replication issues if the hfw has any searchpeers&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 19:56:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/544821#M65203</guid>
      <dc:creator>gurlest</dc:creator>
      <dc:date>2021-03-22T19:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/549038#M65454</link>
      <description>&lt;P&gt;Apparently there is a new version of eStreamer available (&lt;STRONG&gt;4.2.0&lt;/STRONG&gt;).. wondering if anyone used that version?&lt;/P&gt;&lt;P&gt;I'm using 4.0.9 and it stops working every 2, 3 days. when I run the status command below:&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/etc/apps/TA-eStreamer/bin/splencore.sh status&lt;/LI-CODE&gt;&lt;P&gt;getting this error:&lt;/P&gt;&lt;LI-CODE lang="python"&gt;Traceback (most recent call last):
  File "./estreamer/configure.py", line 38, in &amp;lt;module&amp;gt; 
import estreamer.common.convert as convert
  File "/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/__init__.py", line 28, in &amp;lt;module&amp;gt;
    from estreamer.connection import Connection
  File "/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/connection.py", line 23, in &amp;lt;module&amp;gt;
    import ssl
  File "/opt/splunk/lib/python3.7/ssl.py", line 98, in &amp;lt;module&amp;gt;
    import _ssl             # if we can't import it, let the error propagate
ImportError: libssl.so.1.0.0: cannot open shared object file: No such file or directory&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any recommendation to solve this? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 23:54:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/549038#M65454</guid>
      <dc:creator>aydinmo</dc:creator>
      <dc:date>2021-04-22T23:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/550031#M65503</link>
      <description>&lt;P&gt;Can you please state where exactly you added lines 2-4? Did you add the bracket to the end of the file or did you insert it all at lines 2-4?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally, don't forget to re-add the tags file for CIM purposes.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 15:12:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/550031#M65503</guid>
      <dc:creator>rsanders30</dc:creator>
      <dc:date>2021-04-30T15:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore 4.0.9 Add-on for Splunk 8.1.0.1</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/550133#M65504</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Actually I've installed the new released version (4.2.2) and only changed the monitor stanza to monitor the right path:&lt;/P&gt;&lt;LI-CODE lang="python"&gt;[monitor://$SPLUNK_HOME/etc/apps/TA-eStreamer/bin/encore/data/splunk]&lt;/LI-CODE&gt;&lt;P&gt;the new version is working well now, except the clean stanza, which even changing the path doesn't seem to work.&amp;nbsp;I also reduced the time to &lt;U&gt;&lt;STRONG&gt;+10&lt;/STRONG&gt;&lt;/U&gt; minutes, but still no joy:&lt;/P&gt;&lt;LI-CODE lang="python"&gt;clean() {
    # Delete data older than 12 hours -&amp;gt; 720mins
    # find ../../data -type f -mmin +720 -delete
    # correcting path to new path in new version 4.2.2 of TA
    find $SPLUNK_HOME/etc/apps/TA-eStreamer/bin/encore/data/splunk -type f -mmin +10 -delete
}&lt;/LI-CODE&gt;&lt;P&gt;I'm wondering if there is any recommended work around to fix this.&lt;BR /&gt;&lt;BR /&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 02 May 2021 05:00:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-4-0-9-Add-on-for-Splunk-8-1-0-1-Why-am-I/m-p/550133#M65504</guid>
      <dc:creator>aydinmo</dc:creator>
      <dc:date>2021-05-02T05:00:34Z</dc:date>
    </item>
  </channel>
</rss>

