<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not getting data from DELL SonicWall Analytics App in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221068#M73463</link>
    <description>&lt;P&gt;Could you please explain in greater detail your solution? Are you talking about the setting: "Source IP to Use For Collector On A VPN Tunnel"?&lt;/P&gt;</description>
    <pubDate>Thu, 16 Mar 2017 17:00:57 GMT</pubDate>
    <dc:creator>seanduchstein</dc:creator>
    <dc:date>2017-03-16T17:00:57Z</dc:date>
    <item>
      <title>Not getting data from DELL SonicWall Analytics App</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221061#M73456</link>
      <description>&lt;P&gt;Dashboard not working.  I believe I need to edit the sonicwall_firewalls.csv but not sure of the exact context.  This is whats in there now:&lt;/P&gt;

&lt;P&gt;host, firewall_name&lt;BR /&gt;
127.0.0.1, localhost&lt;BR /&gt;
1.1.1.1, "Sample Host"&lt;BR /&gt;
"localhost:2055", "IPFix Convert"&lt;/P&gt;

&lt;P&gt;Note:  I am getting syslog data over UDP port 514 from the same device I'm trying to pull from.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 21:03:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221061#M73456</guid>
      <dc:creator>rodgerkrau</dc:creator>
      <dc:date>2016-04-22T21:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting data from DELL SonicWall Analytics App</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221062#M73457</link>
      <description>&lt;P&gt;It seems unlikely that would prevent the dashboard from working, but unlikely is not the same as impossible.&lt;/P&gt;

&lt;P&gt;You'll probably want to put, as a new line,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;1.2.3.4, "My firewall's name"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;in there, where 1.2.3.4 is its IP and the rest is a string "name" for it.&lt;/P&gt;

&lt;P&gt;If that works, great!&lt;/P&gt;

&lt;P&gt;If not, post back.  It might help quite a bit if you could edit one of the dashboard panels and find the search string in it and paste that in here.  That will tell us a lot about how that app expects to see its data (without making us download the app and examine it ourselves, that is).  &lt;/P&gt;

&lt;P&gt;BTW, USUALLY these sorts of issues end up being index related.  The data is going into a different index than what the dashboards expect, or the permissions are set on the role in such a way that the user logged in doesn't search the particular index needed by default or can't search it at all.  Probably the second biggest reason these sorts of issues crop up is the app just fails to tag (generic word, not &lt;EM&gt;exactly and precisely the "tag" capability inside Splunk&lt;/EM&gt;) your events properly (which can often be an input problem like you aren't assigning the right sourcetype on the input or something, but there are other various reasons for this sometimes too).&lt;/P&gt;</description>
      <pubDate>Sat, 23 Apr 2016 03:04:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221062#M73457</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-04-23T03:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting data from DELL SonicWall Analytics App</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221063#M73458</link>
      <description>&lt;P&gt;stopped the splunk service.  added a new line (didnt remove any lines) and started splunk service. &lt;BR /&gt;
Now get an error: received event for unconfigured/disabled/deleted index='sonicwall' with source='source::dell_ipfix://Dell_IPFIX' host='host::localhost:2055' sourcetype='sourcetype::dell_ipfix' (1 missing total)&lt;/P&gt;

&lt;P&gt;xxx.xxx.xxx.xxx, "My SonicWall"&lt;BR /&gt;
host, firewall_name&lt;BR /&gt;
127.0.0.1, localhost&lt;BR /&gt;
1.1.1.1, "Sample Host"&lt;BR /&gt;
"localhost:2055", "IPFix Convert"&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:32:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221063#M73458</guid>
      <dc:creator>rodgerkrau</dc:creator>
      <dc:date>2020-09-29T09:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting data from DELL SonicWall Analytics App</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221064#M73459</link>
      <description>&lt;P&gt;Here is one of the dashboard search strings: index=sonicwall tid=257 OR tid=357 OR tid=458 | timechart span=1h sum(init_to_resp_octets) as "outbound", sum(resp_to_init_octets) as "inbound" | addtotals&lt;/P&gt;

&lt;P&gt;permissions appear to be correct.  I am an admin on the system&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:32:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221064#M73459</guid>
      <dc:creator>rodgerkrau</dc:creator>
      <dc:date>2020-09-29T09:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting data from DELL SonicWall Analytics App</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221065#M73460</link>
      <description>&lt;P&gt;You have an index with the name "sonicwall"?  Your other comment indicates you've checked that, but that error means .... oh, it probably missed an event while you had services down, that's probably all.  So, try this search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=sonicwall
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What's that give?&lt;/P&gt;

&lt;P&gt;Actually, if that returns hits do &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=sonicwall | count by tid
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That way we can kill two birds with one stone.&lt;/P&gt;

&lt;P&gt;Are you on the IRC or Slack channel?  These sorts of interactive back-and-forth troubleshooting is often easier in that forum (then we can come back here and provide the steps and resolution).&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 14:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221065#M73460</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-04-25T14:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting data from DELL SonicWall Analytics App</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221066#M73461</link>
      <description>&lt;P&gt;ok, I noticed the index was set for "main" so I changed to sonicwall.  index = sonicwall now showing data however dashboards still not populating data..  I can only post on this forum twice a day.  Can we troubleshoot via email? and then post solution once resolved? &lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 12:56:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221066#M73461</guid>
      <dc:creator>rodgerkrau</dc:creator>
      <dc:date>2016-04-26T12:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting data from DELL SonicWall Analytics App</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221067#M73462</link>
      <description>&lt;P&gt;Resolution took a bit of back and forth.&lt;/P&gt;

&lt;P&gt;Deeper inspection of the events he had showed only lines like &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;tid=555 total_data_count=0 total_data_size_kb=0 total_discard_count=0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In his sonicwall index.  This is the same sorts of summary events I got when I tested the app (and I have NO sonicwall), so it became clear the data was NOT actually coming in.&lt;/P&gt;

&lt;P&gt;We double-checked the setup instructions and those did seem to have been completed properly.  Rodgerkrau sniffed some traffic with Wireshark and confirmed that the data wasn't getting there.&lt;/P&gt;

&lt;P&gt;It turned out the router vpn from the sonicwall IP had to be reset to 0.0.0.0 and the data started flowing. &lt;/P&gt;

&lt;P&gt;All is better now!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 11:58:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221067#M73462</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-04-28T11:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting data from DELL SonicWall Analytics App</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221068#M73463</link>
      <description>&lt;P&gt;Could you please explain in greater detail your solution? Are you talking about the setting: "Source IP to Use For Collector On A VPN Tunnel"?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2017 17:00:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Not-getting-data-from-DELL-SonicWall-Analytics-App/m-p/221068#M73463</guid>
      <dc:creator>seanduchstein</dc:creator>
      <dc:date>2017-03-16T17:00:57Z</dc:date>
    </item>
  </channel>
</rss>

