<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco eStreamer eNcore Add-on for Splunk: eNcore process not starting in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/673676#M80091</link>
    <description>&lt;P&gt;Recently we upgraded FMC from 6.x to 7.x and noticed no data was being streamed into the /opt/splunk/etc/apps/TA-eStreamer/bin/encore/data/splunk directory.&amp;nbsp; We then started getting a firewall error when testing the connection..&lt;BR /&gt;&lt;BR /&gt;Does anyone know if FMC 7.x is compatible with the TA-eStreamer add-on?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;./splencore.sh test&lt;BR /&gt;Diagnostics ERROR [no message or attrs]: Could not connect to eStreamer Server at all. Are you sure the host and port are correct? If so then perhaps it is a firewall issue.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jan 2024 17:00:10 GMT</pubDate>
    <dc:creator>computermathguy</dc:creator>
    <dc:date>2024-01-09T17:00:10Z</dc:date>
    <item>
      <title>Cisco eStreamer eNcore Add-on for Splunk: eNcore process not starting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/472374#M58052</link>
      <description>&lt;P&gt;I have a host were TA-eStreamer is deployed, it was working fine last 2018 but it is now not running. This is the estreamer.log when it was working then stopped until the time I tried to start splencore.sh. &lt;/P&gt;

&lt;P&gt;2018-11-22 11:20:50,027 Monitor      INFO     Running. 23229500 handled; average rate 45.3 ev/sec;&lt;BR /&gt;
2018-11-22 11:23:06,795 Monitor      INFO     Running. 23230900 handled; average rate 45.29 ev/sec;&lt;BR /&gt;
2018-11-22 11:23:11,190 Service      INFO     Splunk is not running.&lt;BR /&gt;
2018-11-22 11:23:11,191 Service      INFO     Stopping&lt;BR /&gt;
2018-11-22 11:23:11,691 Controller   INFO     Stopping...&lt;BR /&gt;
2018-11-22 11:23:17,300 SubscriberParser INFO     Stop message received&lt;BR /&gt;
2018-11-22 11:23:27,808 SubscriberParser INFO     Exiting&lt;BR /&gt;
2018-11-22 11:23:27,829 Controller   INFO     Process 22262 (Process-1) exit code: 0&lt;BR /&gt;
2018-11-22 11:23:27,835 Decorator    INFO     Stop message received&lt;BR /&gt;
2018-11-22 11:23:27,840 Decorator    INFO     Error state. Clearing queue&lt;BR /&gt;
2018-11-22 11:23:27,840 Cache        INFO     Saving cache to $SPLUNK_HOME/etc/apps/TA-eStreamer/bin/encore/&lt;BR /&gt;
2018-11-22 11:23:34,042 Decorator    INFO     Exiting&lt;BR /&gt;
2018-11-22 11:23:34,154 Controller   INFO     Process 22263 (Process-2) exit code: 0&lt;BR /&gt;
2018-11-22 11:23:34,155 Transformer  INFO     Stop message received&lt;BR /&gt;
2018-11-22 11:23:34,160 Transformer  INFO     Error state. Clearing queue&lt;BR /&gt;
2018-11-22 11:23:34,160 Transformer  INFO     Exiting&lt;BR /&gt;
2018-11-22 11:23:34,160 Controller   INFO     Process 22264 (Process-3) exit code: 0&lt;BR /&gt;
2018-11-22 11:23:34,161 Writer       INFO     Stop message received&lt;BR /&gt;
2018-11-22 11:23:34,166 Writer       INFO     Error state. Clearing queue&lt;BR /&gt;
2018-11-22 11:23:34,166 Writer       INFO     Exiting&lt;BR /&gt;
2018-11-22 11:23:34,166 Controller   INFO     Process 22266 (Process-4) exit code: 0&lt;BR /&gt;
2018-11-22 11:23:34,166 Monitor      INFO     Stopping Monitor.&lt;BR /&gt;
2018-11-22 11:23:34,331 Controller   INFO     Goodbye&lt;BR /&gt;
2019-10-30 20:07:59,466 Controller   INFO     eNcore version: 3.5.3&lt;/P&gt;

&lt;P&gt;As you can see from the logs that splunk is not running when estreamer logs stopped that time.&lt;/P&gt;

&lt;P&gt;But I've verified before and after I've started splencore.sh that splunk is running, but I still see the same message that splunk is not running.&lt;/P&gt;

&lt;P&gt;2019-10-31 15:44:39,776 Decorator    INFO     Starting process.&lt;BR /&gt;
2019-10-31 15:44:39,777 Transformer  INFO     Starting process.&lt;BR /&gt;
2019-10-31 15:44:39,777 Monitor      INFO     Starting Monitor.&lt;BR /&gt;
2019-10-31 15:44:39,777 Writer       INFO     Starting process.&lt;BR /&gt;
2019-10-31 15:44:39,793 Service      INFO     Splunk is not running.&lt;BR /&gt;
2019-10-31 15:44:39,794 Service      INFO     Stopping&lt;/P&gt;

&lt;P&gt;estreamer.logs doesnt really show me why its failing to start. &lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 07:37:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/472374#M58052</guid>
      <dc:creator>danicarmelo</dc:creator>
      <dc:date>2019-10-31T07:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk: eNcore process not starting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/472375#M58053</link>
      <description>&lt;P&gt;Please update to the latest version of the TA.&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/3662/"&gt;https://splunkbase.splunk.com/app/3662/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you still have the problem just copy / paste new log data in this forum and we'll make a few suggestions.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 17:19:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/472375#M58053</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2019-11-06T17:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk: eNcore process not starting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/472376#M58054</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&lt;BR /&gt;
I have upgraded to the latest version but I am encountering this error message when i am starting encore:&lt;/P&gt;

&lt;P&gt;2019-11-15 21:59:36,939 Diagnostics  ERROR    The FMC eStreamer server has closed the connection. There are a number of possible causes which may show above in the error log.\n\nIf you see no errors then this could be that:\n * the server is shutting down\n * there has been a client authentication failure (please check that your outbound IP address matches that associated with your certificate - note that if your device is subject to NAT then the certificate IP must match the upstream NAT IP)\n * there is a problem with the server. If you are running FMC v6.0, you may need to install "Sourcefire 3D Defense Center S3 Hotfix AZ 6.1.0.3-1"\n&lt;BR /&gt;
2019-11-15 21:59:36,940 Controller   ERROR    ConnectionClosedException: Connection closed\nTraceback (most recent call last):\n  File "$SPLUNK_HOME/etc/apps/TA-eStreamer/bin/encore/estreamer/controller.py", line 244, in start\n    diagnostics.execute()\n  File "$SPLUNK_HOME/etc/apps/TA-eStreamer/bin/encore/estreamer/diagnostics.py", line 96, in execute\n    response = connection.response()\n  File "$SPLUNK_HOME/etc/apps/TA-eStreamer/bin/encore/estreamer/connection.py", line 181, in response\n    dataBuffer = self.__read( 8 )\n  File "$SPLUNK_HOME/etc/apps/TA-eStreamer/bin/encore/estreamer/connection.py", line 158, in __read\n    raise estreamer.ConnectionClosedException('Connection closed')\nConnectionClosedException: Connection closed\n&lt;BR /&gt;
2019-11-15 21:59:36,940 Controller   INFO     Stopping...&lt;BR /&gt;
2019-11-15 21:59:36,940 Monitor      INFO     Stopping Monitor.&lt;BR /&gt;
2019-11-15 21:59:36,941 Controller   INFO     Goodbye&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:58:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/472376#M58054</guid>
      <dc:creator>danicarmelo</dc:creator>
      <dc:date>2020-09-30T02:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk: eNcore process not starting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/472377#M58055</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I am having the same issue with the new app 3.6.8&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/3662/"&gt;https://splunkbase.splunk.com/app/3662/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;and FMC v6.4.0.7&lt;/P&gt;

&lt;P&gt;I can collect the logs a few minutes (cisco:estreamer:data) and then i received &lt;BR /&gt;
"Process subscriberParser is dead"&lt;/P&gt;

&lt;P&gt;any idea ?&lt;BR /&gt;
thanks a lot&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 10:01:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/472377#M58055</guid>
      <dc:creator>vinz2020</dc:creator>
      <dc:date>2020-03-10T10:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk: eNcore process not starting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/556878#M65935</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49294"&gt;@vinz2020&lt;/a&gt;&amp;nbsp; ,&lt;/P&gt;&lt;P&gt;Did you ever manage to resolve this? We are running into the same issue now&lt;/P&gt;&lt;P&gt;We use the app ver. 4.6.0 on Splunk 8.1.3 with an FMC version of 6.6.0 and are encountering the same issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 15:13:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/556878#M65935</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-23T15:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk: eNcore process not starting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/556959#M65947</link>
      <description>&lt;P&gt;Yes I fixed it ... but unfortunately I can't remember how &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now I am running app 4.6, Splunk 8.1.3 and &lt;STRONG&gt;FMC 6.5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 09:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/556959#M65947</guid>
      <dc:creator>vinz2020</dc:creator>
      <dc:date>2021-06-24T09:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk: eNcore process not starting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/557049#M65953</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49294"&gt;@vinz2020&lt;/a&gt;&amp;nbsp; Any thing that you can recollect and provide inputs will be highly appreciated.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 19:15:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/557049#M65953</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-24T19:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk: eNcore process not starting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/558154#M66030</link>
      <description>&lt;P&gt;It would seem 6.4.0 was released with a couple of bugs. My instance just failed 3-4 days after install. Upgrade to 6.4.2.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 12:44:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/558154#M66030</guid>
      <dc:creator>_joe</dc:creator>
      <dc:date>2021-07-02T12:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk: eNcore process not starting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/673676#M80091</link>
      <description>&lt;P&gt;Recently we upgraded FMC from 6.x to 7.x and noticed no data was being streamed into the /opt/splunk/etc/apps/TA-eStreamer/bin/encore/data/splunk directory.&amp;nbsp; We then started getting a firewall error when testing the connection..&lt;BR /&gt;&lt;BR /&gt;Does anyone know if FMC 7.x is compatible with the TA-eStreamer add-on?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;./splencore.sh test&lt;BR /&gt;Diagnostics ERROR [no message or attrs]: Could not connect to eStreamer Server at all. Are you sure the host and port are correct? If so then perhaps it is a firewall issue.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 17:00:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/673676#M80091</guid>
      <dc:creator>computermathguy</dc:creator>
      <dc:date>2024-01-09T17:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk: eNcore process not starting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/682109#M80398</link>
      <description>&lt;P&gt;For me, it turned out to be an incorrect FMC IP. Post proper IP configuration it worked&amp;nbsp;&lt;BR /&gt;Splunk - 9.2.0.1&lt;BR /&gt;eStreamer - 5.2.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 13:56:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-eNcore-process-not/m-p/682109#M80398</guid>
      <dc:creator>vikesh05</dc:creator>
      <dc:date>2024-03-27T13:56:43Z</dc:date>
    </item>
  </channel>
</rss>

