<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sourcefire Encore data ingestion issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/567093#M100759</link>
    <description>&lt;P&gt;Posting an update in the hope that it will help someone.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We had a ticket open with Cisco support and after a few versions of the TA, the most recent eStreamer version 4.8.1&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3662/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3662/&lt;/A&gt;&amp;nbsp; fixed the issue for us.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks! to&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235961"&gt;@skhademd&lt;/a&gt;&amp;nbsp;for delivering the fix.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyone encountering this issue, please upgrade to ver. 4.8.1 of the TA as that seems to have fix the issue.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Sep 2021 10:47:52 GMT</pubDate>
    <dc:creator>vik_splunk</dc:creator>
    <dc:date>2021-09-15T10:47:52Z</dc:date>
    <item>
      <title>Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/555851#M92049</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have recently upgraded from 7.2.6 to 8.1.3 Splunk and since then, we have been having issues with Sourcefire ingestion from FMC.&lt;/P&gt;&lt;P&gt;Splunk and sourcefire version - prior to upgrade - 7.2.6 and 3.0.0&lt;/P&gt;&lt;P&gt;Splunk and sourcefire version - Post upgrade - 8.1.3 and 4.6.0&lt;/P&gt;&lt;P&gt;TA used -&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3662/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3662/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;What we've attempted so far&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;3.0.0&amp;nbsp; with compatibility enabled for Python 2.x - Errors out with&amp;nbsp; Connection reset by peer&lt;BR /&gt;&lt;P&gt;estreamer.subscriber ERROR&amp;nbsp;&amp;nbsp;&amp;nbsp; error: \nTraceback (most recent call last):\n&amp;nbsp; File "/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/subscriber.py", line 198, in start\n&amp;nbsp;&amp;nbsp;&amp;nbsp; self.connection.connect()\n&amp;nbsp; File "/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/connection.py", line 80, in connect\n&amp;nbsp;&amp;nbsp;&amp;nbsp; self.socket.connect( ( host, port ) )\n&amp;nbsp; File "/opt/splunk/lib/python2.7/ssl.py", line 864, in connect\n&amp;nbsp;&amp;nbsp;&amp;nbsp; self._real_connect(addr, False)\n&amp;nbsp; File "/opt/splunk/lib/python2.7/ssl.py", line 855, in _real_connect\n&amp;nbsp;&amp;nbsp;&amp;nbsp; self.do_handshake()\n&amp;nbsp; File "/opt/splunk/lib/python2.7/ssl.py", line 828, in do_handshake\n&amp;nbsp;&amp;nbsp;&amp;nbsp; self._sslobj.do_handshake()\nerror: [Errno 104] Connection reset by peer\n&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;4.6.0 upgraded TA in 8.1.3 - Connection succeeds and collects logs for a while but then, we are met with the errors "Invalid JSON in settings file" followed by Subscriberparser is dead, message - We also found this bug reference, similar to the error -&amp;nbsp;&lt;P&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvy06369" target="_blank" rel="noopener"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCvy06369&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;4.6.0 upgraded TA with compatibility enabled for 2.x - Same as above. Connection succeeds but eventually, stops collection after a while and errors out with the same message as present in 2.&lt;/LI&gt;&lt;LI&gt;Fresh install of 4.6.0 followed by fresh config.&amp;nbsp; Connects fine to FMC but errors out as below&lt;BR /&gt;"&lt;SPAN&gt;Error state. Clearing queue"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;In a nutshell, what used to be a stable stream of logs from FMC is completely broken/fragmented. In all cases, able to use the splencore test to establish successful connection and have restarted the service but no luck.&lt;BR /&gt;&lt;BR /&gt;We have been through all articles in community and as well, all suggested troubleshooting but no luck. Any advice on getting this working is much appreciated.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;- Can you please advise. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 19:13:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/555851#M92049</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-15T19:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/555868#M92050</link>
      <description>&lt;P&gt;Thanks for the message!&amp;nbsp; We're looking at it.&amp;nbsp; Appreciate all the details.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Doug&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 21:56:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/555868#M92050</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2021-06-15T21:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556141#M92077</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp; just wanted to follow up and check if you were able to find anything of interest/ a possible fix?&lt;/P&gt;&lt;P&gt;Meanwhile, we managed to test in a different environment with FMC 6.4.4 and that seems to be stable in comparison.&lt;/P&gt;&lt;P&gt;Versions used - Splunk 8.1.3 , Python 3 , Add on ver. 4.6.0 and FMC 6.4.4&lt;BR /&gt;&lt;BR /&gt;Interestingly, we do see the same error as seen earlier but the key difference is that it does not result in abrupt stoppage of logs. Seems to offer the same pre-upgrade stability.&lt;/P&gt;&lt;P&gt;As can be seen, the estreamer.log stopped at 9:39 EDT yesterday with the same error as mentioned in the bug report. However, subsequent listing of the data folder shows the continuous inflow of logs.&lt;/P&gt;&lt;P&gt;2021-06-16 09:33:32,517 Monitor INFO Running. 697900 handled; average rate 86.8 ev/sec;&lt;BR /&gt;2021-06-16 09:35:31,612 Monitor INFO Running. 697900 handled; average rate 85.52 ev/sec;&lt;BR /&gt;2021-06-16 09:37:31,434 Monitor INFO Running. 698000 handled; average rate 84.29 ev/sec;&lt;BR /&gt;2021-06-16 09:39:31,593 Monitor INFO Running. 698000 handled; average rate 83.09 ev/sec;&lt;BR /&gt;2021-06-16 09:39:32,450 Service ERROR [no message or attrs]: Invalid JSON in settings file&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pwd&lt;BR /&gt;/opt/splunk/etc/apps/TA-eStreamer/bin/encore/data/splunk&lt;BR /&gt;ls -ltr&lt;BR /&gt;Jun 17 04:36 encore.1623902980.log&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 08:41:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556141#M92077</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-17T08:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556566#M92113</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I am also seeing the same issue with the latest TA on Splunk 8.2. Seems like it happens every day or every other day I get the same error and it stops pulling logs.&lt;/P&gt;&lt;P&gt;2021-06-21 08:10:12,573 Monitor INFO Running. 62720000 handled; average rate 1371.82 ev/sec;&lt;BR /&gt;2021-06-21 08:12:11,573 Monitor INFO Running. 62860500 handled; average rate 1371.3 ev/sec;&lt;BR /&gt;2021-06-21 08:14:11,827 Monitor INFO Running. 63002100 handled; average rate 1370.8 ev/sec;&lt;BR /&gt;2021-06-21 08:16:12,215 Monitor INFO Running. 63148100 handled; average rate 1370.4 ev/sec;&lt;BR /&gt;2021-06-21 08:16:43,508 Service ERROR [no message or attrs]: Invalid JSON in settings file&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 17:02:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556566#M92113</guid>
      <dc:creator>elee_splunk</dc:creator>
      <dc:date>2021-06-21T17:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556650#M92122</link>
      <description>&lt;P&gt;Error not withstanding, it seems to be stable as before following our upgrade to FMC 6.4.4.&lt;BR /&gt;&lt;BR /&gt;Appears to have been by the bug noted earlier in this ticket.&lt;/P&gt;&lt;P&gt;To conclude, the error for Invalid JSON.. is still appearing for the new FMC version as well. It continues to ingest logs anyway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Marking this as the solution&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;. Unless you see any fix that is required to the TA, my issue is fixed now. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 09:15:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556650#M92122</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-22T09:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556864#M92150</link>
      <description>&lt;P&gt;Appears that I spoke too soon&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was fine for two days and now, we are back to square one unfortunately with the below errors&lt;/P&gt;&lt;P&gt;This is still an issue and will require a fix. Please advise.&lt;/P&gt;&lt;P&gt;2021-06-23 09:23:53,924 Connection INFO Connecting to &amp;lt;IP&amp;gt;&lt;BR /&gt;2021-06-23 09:23:53,926 Connection INFO Using TLS v1.2&lt;BR /&gt;2021-06-23 09:23:53,926 Transformer INFO Starting process.&lt;BR /&gt;2021-06-23 09:23:53,927 Monitor INFO Starting Monitor.&lt;BR /&gt;2021-06-23 09:23:53,927 Decorator INFO Starting process.&lt;BR /&gt;2021-06-23 09:23:53,928 Transformer DEBUG Transformer&lt;BR /&gt;2021-06-23 09:23:53,928 Decorator DEBUG Decorator&lt;BR /&gt;2021-06-23 09:23:53,928 Writer INFO Starting process.&lt;BR /&gt;2021-06-23 09:23:53,929 Writer DEBUG Writer&lt;BR /&gt;2021-06-23 09:23:53,929 Monitor INFO Starting. 0 handled; average rate 0 ev/sec;&lt;BR /&gt;2021-06-23 09:25:54,081 Controller INFO Process subscriberParser is dead.&lt;BR /&gt;2021-06-23 09:25:54,081 Monitor INFO Running. 0 handled; average rate 0 ev/sec;&lt;BR /&gt;2021-06-23 09:25:54,133 Controller INFO Stopping...&lt;BR /&gt;2021-06-23 09:25:54,134 Controller INFO Process 7091 (Process-1) exit code: 1&lt;BR /&gt;2021-06-23 09:25:54,134 Decorator INFO Stop message received&lt;BR /&gt;2021-06-23 09:25:54,140 Decorator INFO Error state. Clearing queue&lt;BR /&gt;2021-06-23 09:25:54,141 Decorator INFO Exiting&lt;BR /&gt;2021-06-23 09:25:54,141 Controller INFO Process 7092 (Process-2) exit code: 0&lt;BR /&gt;2021-06-23 09:25:54,146 Transformer INFO Stop message received&lt;BR /&gt;2021-06-23 09:25:54,152 Transformer INFO Error state. Clearing queue&lt;BR /&gt;2021-06-23 09:25:54,152 Transformer INFO Exiting&lt;BR /&gt;2021-06-23 09:25:54,152 Controller INFO Process 7093 (Process-3) exit code: 0&lt;BR /&gt;2021-06-23 09:25:54,157 Writer INFO Stop message received&lt;BR /&gt;2021-06-23 09:25:54,163 Writer INFO Error state. Clearing queue&lt;BR /&gt;2021-06-23 09:25:54,163 Writer INFO Exiting&lt;BR /&gt;2021-06-23 09:25:54,163 Controller INFO Process 7096 (Process-4) exit code: 0&lt;BR /&gt;2021-06-23 09:25:54,163 Monitor INFO Stopping Monitor.&lt;BR /&gt;2021-06-23 09:25:54,333 Controller INFO Goodbye&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 13:31:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556864#M92150</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-23T13:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556879#M92151</link>
      <description>&lt;P&gt;Same here, happening to me on a daily basis&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 15:18:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556879#M92151</guid>
      <dc:creator>elee_splunk</dc:creator>
      <dc:date>2021-06-23T15:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557053#M92171</link>
      <description>&lt;P&gt;Hmmm.. Just putting it out there. Not sure if it contributes to the issue&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235641"&gt;@elee_splunk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What Linux version are you running Splunk on the specific machine?&lt;/P&gt;&lt;P&gt;The noticeable difference in our environment is as below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%"&gt;FMC&lt;/TD&gt;&lt;TD width="25%"&gt;RHEL&lt;/TD&gt;&lt;TD width="25%"&gt;Splunk&lt;/TD&gt;&lt;TD width="12.5%"&gt;estreamer TA&lt;/TD&gt;&lt;TD width="6.25%"&gt;customizations if any&lt;/TD&gt;&lt;TD width="6.25%"&gt;Status&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;6.6.4&lt;/TD&gt;&lt;TD width="25%"&gt;6.x&lt;/TD&gt;&lt;TD width="25%"&gt;8.1.3&lt;/TD&gt;&lt;TD width="12.5%"&gt;4.6.0&lt;/TD&gt;&lt;TD width="6.25%"&gt;sourcetype slightly changed&amp;nbsp;&lt;/TD&gt;&lt;TD width="6.25%"&gt;Completely broken without a semblance of stability&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;6.6.4&lt;/TD&gt;&lt;TD width="25%"&gt;7.x&lt;/TD&gt;&lt;TD width="25%"&gt;8.1.3&lt;/TD&gt;&lt;TD width="12.5%"&gt;4.6.0&lt;/TD&gt;&lt;TD width="6.25%"&gt;default sourcetype&lt;/TD&gt;&lt;TD width="6.25%"&gt;Pretty stable&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp; thoughts?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 19:21:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557053#M92171</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-24T19:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557058#M92172</link>
      <description>&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="26.01010101010101%"&gt;FMC&lt;/TD&gt;&lt;TD width="23.98989898989899%"&gt;Ubuntu&lt;/TD&gt;&lt;TD width="25%"&gt;Splunk&lt;/TD&gt;&lt;TD width="12.5%"&gt;estreamer TA&lt;/TD&gt;&lt;TD width="6.25%"&gt;customizations if any&lt;/TD&gt;&lt;TD width="6.25%"&gt;Status&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="26.01010101010101%"&gt;6.6.4&lt;/TD&gt;&lt;TD width="23.98989898989899%"&gt;20.04.2 LTS&lt;/TD&gt;&lt;TD width="25%"&gt;8.2&lt;/TD&gt;&lt;TD width="12.5%"&gt;4.6.0&lt;/TD&gt;&lt;TD width="6.25%"&gt;default sourcetype&lt;/TD&gt;&lt;TD width="6.25%"&gt;Intermittent&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have to stop the estreamer service and start it back up to get it going at least once every day or 2 days. When that doesn't work I have to reboot the whole server.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 19:57:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557058#M92172</guid>
      <dc:creator>elee_splunk</dc:creator>
      <dc:date>2021-06-24T19:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557598#M92282</link>
      <description>&lt;P&gt;Hi Douglas,&lt;/P&gt;&lt;P&gt;it seems I´m facing the same issue.&lt;BR /&gt;&lt;BR /&gt;Version 4.0.9 suddenly stopped working, and ran into the following error:&lt;BR /&gt;&lt;SPAN&gt;Decorator ERROR [no message or attrs]: 'View' object has no attribute '_view__isHex'...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;As I did not get it to work again (restart,reboots...), I tried the new 4.6.0 release.&lt;BR /&gt;&lt;BR /&gt;In the beginning it looked fine (besides missing status and clean options in splencore.sh that I added again) , logs were written and ingested into Splunk.&lt;BR /&gt;After almost 3 hours the error "&lt;SPAN&gt;Service ERROR [no message or attrs]: Invalid JSON in settings file" appeared in the estreamer.log. But logs where still written and input to splunk worked - except estreamer.log: monitor logs stopped and no other message was written.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Suddenly more then 7 hours after the "invalid JSON in settings file" error, fmc logs stopped, too.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;After restart of the client, it started working again. The "invalid JSON.." error already reappeared after 2 hours. This time I did not wait for fmc logs to stop and directly restarted the client. Now since 5 hours, no error but according to the other feedback in here, it´s only a matter of time.&lt;/P&gt;&lt;P&gt;Did you already identify any issues?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Alex&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 13:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557598#M92282</guid>
      <dc:creator>AlexS</dc:creator>
      <dc:date>2021-06-29T13:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557662#M92293</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/77176"&gt;@vik_splunk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've switched back to my old HF and its been very stable.&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="26.01010101010101%"&gt;FMC&lt;/TD&gt;&lt;TD width="23.98989898989899%"&gt;Ubuntu&lt;/TD&gt;&lt;TD width="25%"&gt;Splunk&lt;/TD&gt;&lt;TD width="12.5%"&gt;estreamer TA&lt;/TD&gt;&lt;TD width="6.25%"&gt;customizations if any&lt;/TD&gt;&lt;TD width="6.25%"&gt;Status&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="26.01010101010101%"&gt;6.6.4&lt;/TD&gt;&lt;TD width="23.98989898989899%"&gt;18.04.5 LTS&lt;/TD&gt;&lt;TD width="25%"&gt;7.2.10&lt;/TD&gt;&lt;TD width="12.5%"&gt;3.6.8&lt;/TD&gt;&lt;TD width="6.25%"&gt;default sourcetype&lt;/TD&gt;&lt;TD width="6.25%"&gt;Stable&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 18:44:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557662#M92293</guid>
      <dc:creator>elee_splunk</dc:creator>
      <dc:date>2021-06-29T18:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557697#M92298</link>
      <description>&lt;P&gt;Please email a link to this thread to &lt;A href="mailto:encore-community@cisco.com" target="_blank"&gt;encore-community@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Doug&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 20:56:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557697#M92298</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2021-06-29T20:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557776#M92309</link>
      <description>&lt;P&gt;Just did,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 09:51:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557776#M92309</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-30T09:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557777#M92310</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235641"&gt;@elee_splunk&lt;/a&gt;&amp;nbsp; That's good to hear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appears Python 2 script seems to offer stability in your case. In our environment, it's a bit puzzling in the fact that we have one forwarder ingesting logs without issues in the new version while the prod environment seems to throw errors.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 09:53:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557777#M92310</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-30T09:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557843#M92317</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We believe this is a bug in the splencore.sh script, specifically with the clean command, in a prior update we modified the location of the ingest directory,&amp;nbsp; this script was not updated to reflect the new location which we believe is causing the error you are seeing.&amp;nbsp; Please perform the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; Disable the clean script&lt;/P&gt;&lt;P&gt;2) Modify the splencore.sh to point the proper ingest directory&lt;/P&gt;&lt;P&gt;3) Upgrade the TA to 4.6.1, which includes the modification above&lt;/P&gt;&lt;P&gt;If problems continue please open a ticket with TAC support so we can collect additional trouble shoot files&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seyed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 15:22:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557843#M92317</guid>
      <dc:creator>skhademd</dc:creator>
      <dc:date>2021-06-30T15:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557848#M92320</link>
      <description>&lt;P&gt;Will try that. I don't believe we have access to the 4.6.1 version of the TA yet. Doesn't look like it's published to splunkbase.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 15:27:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557848#M92320</guid>
      <dc:creator>elee_splunk</dc:creator>
      <dc:date>2021-06-30T15:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557851#M92322</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235961"&gt;@skhademd&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The new TA is available now. Will validate and confirm.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 16:10:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557851#M92322</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-30T16:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557895#M92326</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235961"&gt;@skhademd&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have installed 4.6.1 afresh and configured from scratch to connect to our FMCs(with DEBUG logging enabled. Collection has resumed in Splunk. However, here are the initial observations.&lt;/P&gt;&lt;P&gt;1)Data collection is always 10-15 minutes behind current time.&lt;/P&gt;&lt;P&gt;2)Checking estreamer logs, the events per second is consistently on the decrease. Not sure if it's on the path to stoppage of collection&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-06-30 14:19:58,631 Monitor INFO Running. 103400 handled; average rate 25.34 ev/sec;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:20:08,633 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:20:23,145 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:20:33,658 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:20:47,175 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:20:57,684 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:08,190 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:18,699 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:29,209 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:36,240 Receiver DEBUG Got null message.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:47,252 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:57,764 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:58,274 Monitor INFO Running. 103400 handled; average rate 24.62 ev/sec;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:22:08,267 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:22:18,778 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:22:29,289 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:22:36,301 Receiver DEBUG Got null message.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:22:46,312 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:22:56,822 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:23:14,347 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:23:29,368 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:23:43,386 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:23:47,402 Monitor INFO Running. 103400 handled; average rate 23.93 ev/sec;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:23:57,406 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:24:07,915 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:24:22,436 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:24:32,946 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:24:43,454 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:24:53,959 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:04,471 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:11,492 Receiver DEBUG Got null message.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:21,498 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:32,006 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:42,518 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:53,028 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:53,542 Monitor INFO Running. 103400 handled; average rate 23.29 ev/sec;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:26:03,540 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:26:11,564 Receiver DEBUG Got null message.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:26:21,563 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:26:32,076 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:26:42,584 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:26:53,089 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:27:03,601 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:27:11,626 Receiver DEBUG Got null message.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:27:21,636 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:27:32,149 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:27:49,673 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:28:00,183 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:28:00,697 Monitor INFO Running. 103400 handled; average rate 22.67 ev/sec;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:28:10,688 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:28:21,193 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:28:31,701 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3)Clean up script has an issue with absolute vs relative path I suspect , as I notice this error in Splunk internal logs.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;06-30-2021 14:17:27.087 -0400 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/TA-eStreamer/bin/splencore.sh clean" find: `./encore/data': No such file or directory&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 18:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557895#M92326</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-30T18:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/558007#M92334</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235961"&gt;@skhademd&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;Unfortunately, the new version of 4.6.1 didn't help either. The same error is back, as always, slightly later in the same day.&lt;/P&gt;&lt;P&gt;In parallel, we have had our Network admins raise a ticket with Cisco. Cisco has acknowledged the problem and raised a bug as can be seen below. I will e-mail details of the case to the e-mail address shared by Doug.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a bug open for this, but it looks like there is no root cause found yet:&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy79722" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy79722&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Logs as shown below.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2021-06-30 18:21:51,735 Monitor INFO Running. 104600 handled; average rate 5.62 ev/sec;&lt;BR /&gt;2021-06-30 18:22:19,262 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:22:41,791 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:22:52,297 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:23:02,798 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:23:13,307 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:23:23,836 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:23:34,343 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:23:52,872 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:23:53,384 Monitor INFO Running. 104600 handled; average rate 5.59 ev/sec;&lt;BR /&gt;2021-06-30 18:24:11,898 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:24:22,400 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:24:32,907 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:24:43,413 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:24:53,929 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:25:00,952 Receiver DEBUG Got null message.&lt;BR /&gt;2021-06-30 18:25:15,971 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:25:26,472 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:25:45,003 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:25:51,028 Monitor INFO Running. 104700 handled; average rate 5.56 ev/sec;&lt;BR /&gt;2021-06-30 18:26:11,040 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:26:21,550 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:26:32,058 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:26:42,569 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:26:53,076 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:27:00,099 Receiver DEBUG Got null message.&lt;BR /&gt;2021-06-30 18:27:10,099 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:27:20,612 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:27:31,123 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:27:41,635 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:27:46,163 Monitor INFO Running. 104700 handled; average rate 5.52 ev/sec;&lt;BR /&gt;2021-06-30 18:27:56,154 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:28:10,174 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:28:25,192 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:28:41,212 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:29:05,236 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:29:15,746 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:29:32,268 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:29:45,291 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:29:55,802 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:29:56,312 Monitor INFO Running. 104700 handled; average rate 5.49 ev/sec;&lt;BR /&gt;2021-06-30 18:30:06,304 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:30:17,330 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:30:34,346 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:30:47,081 Service ERROR [no message or attrs]: Invalid JSON in settings file&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 08:15:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/558007#M92334</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-07-01T08:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/558030#M92338</link>
      <description>&lt;P&gt;I compared the new 4.6.1 version and for me issue is also not fixed. The changes necessary for the cleaning to run, I already implemented before.&lt;/P&gt;&lt;P&gt;For now I added another script input to call splencore.sh with a stop statement every x hours, so the service gets restarted regularly. The error appears after random time.&amp;nbsp; Last time error appeared&amp;nbsp; after 45 minutes, but the time before it was running more than 10 hours.&lt;BR /&gt;And still same behavior, logging continues to work after the error is logged but stops some time later.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 13:53:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/558030#M92338</guid>
      <dc:creator>AlexS</dc:creator>
      <dc:date>2021-07-01T13:53:57Z</dc:date>
    </item>
  </channel>
</rss>

