<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Splunk for Snort only displaying data from 12AM to 1AM? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102335#M7135</link>
    <description>&lt;P&gt;For an alert @ 11/02-19:22:19.445432  &lt;/P&gt;

&lt;P&gt;What is the .445432 part of that alert?  is it milliseconds? &lt;/P&gt;</description>
    <pubDate>Fri, 20 Mar 2015 20:29:08 GMT</pubDate>
    <dc:creator>jbyrge0</dc:creator>
    <dc:date>2015-03-20T20:29:08Z</dc:date>
    <item>
      <title>Why is Splunk for Snort only displaying data from 12AM to 1AM?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102328#M7128</link>
      <description>&lt;P&gt;OK I am not crazy here I've seen this on two different machines that I've been running SplunkforSnort on. &lt;/P&gt;

&lt;P&gt;I set up the devices to pull from the '/var/log/snort/alert' log on the box and give them a manual sourcetype of 'snort'. When I first set both boxes up things worked great. Then after about 5-7 days the application exihibits a strange behavior. It only displays the data from 12am to 1am. Has anyone else experienced this? &lt;/P&gt;

&lt;P&gt;When I tail -f the log file I see snort alerts coming in and even when I set SplunkforSnort to 1min realtime I see the number of scanned events increase but the results shows as zero. &lt;/P&gt;

&lt;P&gt;I am using snort 2.9.0.4 and Splunk 4.2.3 if that helps. &lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2011 12:31:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102328#M7128</guid>
      <dc:creator>rbt111</dc:creator>
      <dc:date>2011-11-02T12:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk for Snort only displaying data from 12AM to 1AM?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102329#M7129</link>
      <description>&lt;P&gt;Splunk for Snort relies on a number of field extractions to work. If you manually search for sourcetype="snort" in the default search app, do you get results with both correct timestamps and correct field extractions, for instance do you see the "src_ip" and "signature" fields to the left?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2011 13:05:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102329#M7129</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-11-02T13:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk for Snort only displaying data from 12AM to 1AM?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102330#M7130</link>
      <description>&lt;P&gt;I went to the default search app and entered sourcetype="snort" as you specified. It appears to be showing the same thing that the SplunkforSnort app shows meaning I can see scanned events incrementing but the number of matching events remains at zero. I do not see any of the field extractions in the left column with Field Discovery in the on position.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2011 14:01:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102330#M7130</guid>
      <dc:creator>rbt111</dc:creator>
      <dc:date>2011-11-02T14:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk for Snort only displaying data from 12AM to 1AM?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102331#M7131</link>
      <description>&lt;P&gt;If there are no matching events you're having a problem getting the snort events into Splunk. The scanned events you're seeing that is incrementing is simply ALL events in Splunk's index. If no events with sourcetype "snort" are found, it's because no such events exist in the index. Check your input.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2011 15:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102331#M7131</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-11-02T15:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk for Snort only displaying data from 12AM to 1AM?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102332#M7132</link>
      <description>&lt;P&gt;Thank you for your assistance Ayn.&lt;/P&gt;

&lt;P&gt;I see what is going on now my timestamp got messed up.&lt;/P&gt;

&lt;P&gt;Example I'm showing  &lt;/P&gt;

&lt;P&gt;2/19/11&lt;BR /&gt;
7:22:19.445 PM&lt;/P&gt;

&lt;P&gt;For an alert @  11/02-19:22:19.445432 &lt;/P&gt;

&lt;P&gt;It looks like I may need to modify something in props.conf but I'm not 100% sure. &lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2011 00:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102332#M7132</guid>
      <dc:creator>rbt111</dc:creator>
      <dc:date>2011-11-03T00:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk for Snort only displaying data from 12AM to 1AM?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102333#M7133</link>
      <description>&lt;P&gt;OK it appears to be working now. Just a simple matter of using the snort command with -y to include the year in the logs.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2011 03:53:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102333#M7133</guid>
      <dc:creator>rbt111</dc:creator>
      <dc:date>2011-11-03T03:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk for Snort only displaying data from 12AM to 1AM?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102334#M7134</link>
      <description>&lt;P&gt;Excellent. Do let me know if you have any more questions, comments or suggestions regarding the Snort app (I wrote it), and please vote it up if you find it useful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Also please mark my (or your) answer as accepted so it shows clearly on the site that this question is closed.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2011 05:24:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102334#M7134</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-11-03T05:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk for Snort only displaying data from 12AM to 1AM?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102335#M7135</link>
      <description>&lt;P&gt;For an alert @ 11/02-19:22:19.445432  &lt;/P&gt;

&lt;P&gt;What is the .445432 part of that alert?  is it milliseconds? &lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2015 20:29:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-for-Snort-only-displaying-data-from-12AM-to-1AM/m-p/102335#M7135</guid>
      <dc:creator>jbyrge0</dc:creator>
      <dc:date>2015-03-20T20:29:08Z</dc:date>
    </item>
  </channel>
</rss>

