<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sourcefire Encore data ingestion issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/570103#M101053</link>
    <description>&lt;P&gt;Sorry I completely missed this from earlier&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170984"&gt;@_joe&lt;/a&gt;&amp;nbsp;. We did not have to add the alwaysattempt.. setting and it was stable for 2-3 weeks. We have quite intensive volume of logging and it did cope well.&lt;/P&gt;&lt;P&gt;3 weeks later, we had failure with the same Invalid JSON error and just had to restart encore. The issue has been reported to Cisco and they are investigating. Meanwhile, our workaround is still the tried and tested encore service restart. Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 07 Oct 2021 18:26:51 GMT</pubDate>
    <dc:creator>vik_splunk</dc:creator>
    <dc:date>2021-10-07T18:26:51Z</dc:date>
    <item>
      <title>Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/555851#M92049</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have recently upgraded from 7.2.6 to 8.1.3 Splunk and since then, we have been having issues with Sourcefire ingestion from FMC.&lt;/P&gt;&lt;P&gt;Splunk and sourcefire version - prior to upgrade - 7.2.6 and 3.0.0&lt;/P&gt;&lt;P&gt;Splunk and sourcefire version - Post upgrade - 8.1.3 and 4.6.0&lt;/P&gt;&lt;P&gt;TA used -&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3662/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3662/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;What we've attempted so far&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;3.0.0&amp;nbsp; with compatibility enabled for Python 2.x - Errors out with&amp;nbsp; Connection reset by peer&lt;BR /&gt;&lt;P&gt;estreamer.subscriber ERROR&amp;nbsp;&amp;nbsp;&amp;nbsp; error: \nTraceback (most recent call last):\n&amp;nbsp; File "/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/subscriber.py", line 198, in start\n&amp;nbsp;&amp;nbsp;&amp;nbsp; self.connection.connect()\n&amp;nbsp; File "/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/connection.py", line 80, in connect\n&amp;nbsp;&amp;nbsp;&amp;nbsp; self.socket.connect( ( host, port ) )\n&amp;nbsp; File "/opt/splunk/lib/python2.7/ssl.py", line 864, in connect\n&amp;nbsp;&amp;nbsp;&amp;nbsp; self._real_connect(addr, False)\n&amp;nbsp; File "/opt/splunk/lib/python2.7/ssl.py", line 855, in _real_connect\n&amp;nbsp;&amp;nbsp;&amp;nbsp; self.do_handshake()\n&amp;nbsp; File "/opt/splunk/lib/python2.7/ssl.py", line 828, in do_handshake\n&amp;nbsp;&amp;nbsp;&amp;nbsp; self._sslobj.do_handshake()\nerror: [Errno 104] Connection reset by peer\n&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;4.6.0 upgraded TA in 8.1.3 - Connection succeeds and collects logs for a while but then, we are met with the errors "Invalid JSON in settings file" followed by Subscriberparser is dead, message - We also found this bug reference, similar to the error -&amp;nbsp;&lt;P&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvy06369" target="_blank" rel="noopener"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCvy06369&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;4.6.0 upgraded TA with compatibility enabled for 2.x - Same as above. Connection succeeds but eventually, stops collection after a while and errors out with the same message as present in 2.&lt;/LI&gt;&lt;LI&gt;Fresh install of 4.6.0 followed by fresh config.&amp;nbsp; Connects fine to FMC but errors out as below&lt;BR /&gt;"&lt;SPAN&gt;Error state. Clearing queue"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;In a nutshell, what used to be a stable stream of logs from FMC is completely broken/fragmented. In all cases, able to use the splencore test to establish successful connection and have restarted the service but no luck.&lt;BR /&gt;&lt;BR /&gt;We have been through all articles in community and as well, all suggested troubleshooting but no luck. Any advice on getting this working is much appreciated.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;- Can you please advise. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 19:13:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/555851#M92049</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-15T19:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/555868#M92050</link>
      <description>&lt;P&gt;Thanks for the message!&amp;nbsp; We're looking at it.&amp;nbsp; Appreciate all the details.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Doug&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 21:56:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/555868#M92050</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2021-06-15T21:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556141#M92077</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp; just wanted to follow up and check if you were able to find anything of interest/ a possible fix?&lt;/P&gt;&lt;P&gt;Meanwhile, we managed to test in a different environment with FMC 6.4.4 and that seems to be stable in comparison.&lt;/P&gt;&lt;P&gt;Versions used - Splunk 8.1.3 , Python 3 , Add on ver. 4.6.0 and FMC 6.4.4&lt;BR /&gt;&lt;BR /&gt;Interestingly, we do see the same error as seen earlier but the key difference is that it does not result in abrupt stoppage of logs. Seems to offer the same pre-upgrade stability.&lt;/P&gt;&lt;P&gt;As can be seen, the estreamer.log stopped at 9:39 EDT yesterday with the same error as mentioned in the bug report. However, subsequent listing of the data folder shows the continuous inflow of logs.&lt;/P&gt;&lt;P&gt;2021-06-16 09:33:32,517 Monitor INFO Running. 697900 handled; average rate 86.8 ev/sec;&lt;BR /&gt;2021-06-16 09:35:31,612 Monitor INFO Running. 697900 handled; average rate 85.52 ev/sec;&lt;BR /&gt;2021-06-16 09:37:31,434 Monitor INFO Running. 698000 handled; average rate 84.29 ev/sec;&lt;BR /&gt;2021-06-16 09:39:31,593 Monitor INFO Running. 698000 handled; average rate 83.09 ev/sec;&lt;BR /&gt;2021-06-16 09:39:32,450 Service ERROR [no message or attrs]: Invalid JSON in settings file&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pwd&lt;BR /&gt;/opt/splunk/etc/apps/TA-eStreamer/bin/encore/data/splunk&lt;BR /&gt;ls -ltr&lt;BR /&gt;Jun 17 04:36 encore.1623902980.log&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 08:41:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556141#M92077</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-17T08:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556566#M92113</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I am also seeing the same issue with the latest TA on Splunk 8.2. Seems like it happens every day or every other day I get the same error and it stops pulling logs.&lt;/P&gt;&lt;P&gt;2021-06-21 08:10:12,573 Monitor INFO Running. 62720000 handled; average rate 1371.82 ev/sec;&lt;BR /&gt;2021-06-21 08:12:11,573 Monitor INFO Running. 62860500 handled; average rate 1371.3 ev/sec;&lt;BR /&gt;2021-06-21 08:14:11,827 Monitor INFO Running. 63002100 handled; average rate 1370.8 ev/sec;&lt;BR /&gt;2021-06-21 08:16:12,215 Monitor INFO Running. 63148100 handled; average rate 1370.4 ev/sec;&lt;BR /&gt;2021-06-21 08:16:43,508 Service ERROR [no message or attrs]: Invalid JSON in settings file&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 17:02:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556566#M92113</guid>
      <dc:creator>elee_splunk</dc:creator>
      <dc:date>2021-06-21T17:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556650#M92122</link>
      <description>&lt;P&gt;Error not withstanding, it seems to be stable as before following our upgrade to FMC 6.4.4.&lt;BR /&gt;&lt;BR /&gt;Appears to have been by the bug noted earlier in this ticket.&lt;/P&gt;&lt;P&gt;To conclude, the error for Invalid JSON.. is still appearing for the new FMC version as well. It continues to ingest logs anyway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Marking this as the solution&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;. Unless you see any fix that is required to the TA, my issue is fixed now. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 09:15:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556650#M92122</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-22T09:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556864#M92150</link>
      <description>&lt;P&gt;Appears that I spoke too soon&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was fine for two days and now, we are back to square one unfortunately with the below errors&lt;/P&gt;&lt;P&gt;This is still an issue and will require a fix. Please advise.&lt;/P&gt;&lt;P&gt;2021-06-23 09:23:53,924 Connection INFO Connecting to &amp;lt;IP&amp;gt;&lt;BR /&gt;2021-06-23 09:23:53,926 Connection INFO Using TLS v1.2&lt;BR /&gt;2021-06-23 09:23:53,926 Transformer INFO Starting process.&lt;BR /&gt;2021-06-23 09:23:53,927 Monitor INFO Starting Monitor.&lt;BR /&gt;2021-06-23 09:23:53,927 Decorator INFO Starting process.&lt;BR /&gt;2021-06-23 09:23:53,928 Transformer DEBUG Transformer&lt;BR /&gt;2021-06-23 09:23:53,928 Decorator DEBUG Decorator&lt;BR /&gt;2021-06-23 09:23:53,928 Writer INFO Starting process.&lt;BR /&gt;2021-06-23 09:23:53,929 Writer DEBUG Writer&lt;BR /&gt;2021-06-23 09:23:53,929 Monitor INFO Starting. 0 handled; average rate 0 ev/sec;&lt;BR /&gt;2021-06-23 09:25:54,081 Controller INFO Process subscriberParser is dead.&lt;BR /&gt;2021-06-23 09:25:54,081 Monitor INFO Running. 0 handled; average rate 0 ev/sec;&lt;BR /&gt;2021-06-23 09:25:54,133 Controller INFO Stopping...&lt;BR /&gt;2021-06-23 09:25:54,134 Controller INFO Process 7091 (Process-1) exit code: 1&lt;BR /&gt;2021-06-23 09:25:54,134 Decorator INFO Stop message received&lt;BR /&gt;2021-06-23 09:25:54,140 Decorator INFO Error state. Clearing queue&lt;BR /&gt;2021-06-23 09:25:54,141 Decorator INFO Exiting&lt;BR /&gt;2021-06-23 09:25:54,141 Controller INFO Process 7092 (Process-2) exit code: 0&lt;BR /&gt;2021-06-23 09:25:54,146 Transformer INFO Stop message received&lt;BR /&gt;2021-06-23 09:25:54,152 Transformer INFO Error state. Clearing queue&lt;BR /&gt;2021-06-23 09:25:54,152 Transformer INFO Exiting&lt;BR /&gt;2021-06-23 09:25:54,152 Controller INFO Process 7093 (Process-3) exit code: 0&lt;BR /&gt;2021-06-23 09:25:54,157 Writer INFO Stop message received&lt;BR /&gt;2021-06-23 09:25:54,163 Writer INFO Error state. Clearing queue&lt;BR /&gt;2021-06-23 09:25:54,163 Writer INFO Exiting&lt;BR /&gt;2021-06-23 09:25:54,163 Controller INFO Process 7096 (Process-4) exit code: 0&lt;BR /&gt;2021-06-23 09:25:54,163 Monitor INFO Stopping Monitor.&lt;BR /&gt;2021-06-23 09:25:54,333 Controller INFO Goodbye&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 13:31:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556864#M92150</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-23T13:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556879#M92151</link>
      <description>&lt;P&gt;Same here, happening to me on a daily basis&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 15:18:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/556879#M92151</guid>
      <dc:creator>elee_splunk</dc:creator>
      <dc:date>2021-06-23T15:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557053#M92171</link>
      <description>&lt;P&gt;Hmmm.. Just putting it out there. Not sure if it contributes to the issue&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235641"&gt;@elee_splunk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What Linux version are you running Splunk on the specific machine?&lt;/P&gt;&lt;P&gt;The noticeable difference in our environment is as below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%"&gt;FMC&lt;/TD&gt;&lt;TD width="25%"&gt;RHEL&lt;/TD&gt;&lt;TD width="25%"&gt;Splunk&lt;/TD&gt;&lt;TD width="12.5%"&gt;estreamer TA&lt;/TD&gt;&lt;TD width="6.25%"&gt;customizations if any&lt;/TD&gt;&lt;TD width="6.25%"&gt;Status&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;6.6.4&lt;/TD&gt;&lt;TD width="25%"&gt;6.x&lt;/TD&gt;&lt;TD width="25%"&gt;8.1.3&lt;/TD&gt;&lt;TD width="12.5%"&gt;4.6.0&lt;/TD&gt;&lt;TD width="6.25%"&gt;sourcetype slightly changed&amp;nbsp;&lt;/TD&gt;&lt;TD width="6.25%"&gt;Completely broken without a semblance of stability&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;6.6.4&lt;/TD&gt;&lt;TD width="25%"&gt;7.x&lt;/TD&gt;&lt;TD width="25%"&gt;8.1.3&lt;/TD&gt;&lt;TD width="12.5%"&gt;4.6.0&lt;/TD&gt;&lt;TD width="6.25%"&gt;default sourcetype&lt;/TD&gt;&lt;TD width="6.25%"&gt;Pretty stable&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp; thoughts?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 19:21:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557053#M92171</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-24T19:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557058#M92172</link>
      <description>&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="26.01010101010101%"&gt;FMC&lt;/TD&gt;&lt;TD width="23.98989898989899%"&gt;Ubuntu&lt;/TD&gt;&lt;TD width="25%"&gt;Splunk&lt;/TD&gt;&lt;TD width="12.5%"&gt;estreamer TA&lt;/TD&gt;&lt;TD width="6.25%"&gt;customizations if any&lt;/TD&gt;&lt;TD width="6.25%"&gt;Status&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="26.01010101010101%"&gt;6.6.4&lt;/TD&gt;&lt;TD width="23.98989898989899%"&gt;20.04.2 LTS&lt;/TD&gt;&lt;TD width="25%"&gt;8.2&lt;/TD&gt;&lt;TD width="12.5%"&gt;4.6.0&lt;/TD&gt;&lt;TD width="6.25%"&gt;default sourcetype&lt;/TD&gt;&lt;TD width="6.25%"&gt;Intermittent&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have to stop the estreamer service and start it back up to get it going at least once every day or 2 days. When that doesn't work I have to reboot the whole server.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 19:57:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557058#M92172</guid>
      <dc:creator>elee_splunk</dc:creator>
      <dc:date>2021-06-24T19:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557598#M92282</link>
      <description>&lt;P&gt;Hi Douglas,&lt;/P&gt;&lt;P&gt;it seems I´m facing the same issue.&lt;BR /&gt;&lt;BR /&gt;Version 4.0.9 suddenly stopped working, and ran into the following error:&lt;BR /&gt;&lt;SPAN&gt;Decorator ERROR [no message or attrs]: 'View' object has no attribute '_view__isHex'...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;As I did not get it to work again (restart,reboots...), I tried the new 4.6.0 release.&lt;BR /&gt;&lt;BR /&gt;In the beginning it looked fine (besides missing status and clean options in splencore.sh that I added again) , logs were written and ingested into Splunk.&lt;BR /&gt;After almost 3 hours the error "&lt;SPAN&gt;Service ERROR [no message or attrs]: Invalid JSON in settings file" appeared in the estreamer.log. But logs where still written and input to splunk worked - except estreamer.log: monitor logs stopped and no other message was written.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Suddenly more then 7 hours after the "invalid JSON in settings file" error, fmc logs stopped, too.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;After restart of the client, it started working again. The "invalid JSON.." error already reappeared after 2 hours. This time I did not wait for fmc logs to stop and directly restarted the client. Now since 5 hours, no error but according to the other feedback in here, it´s only a matter of time.&lt;/P&gt;&lt;P&gt;Did you already identify any issues?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Alex&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 13:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557598#M92282</guid>
      <dc:creator>AlexS</dc:creator>
      <dc:date>2021-06-29T13:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557662#M92293</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/77176"&gt;@vik_splunk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've switched back to my old HF and its been very stable.&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="26.01010101010101%"&gt;FMC&lt;/TD&gt;&lt;TD width="23.98989898989899%"&gt;Ubuntu&lt;/TD&gt;&lt;TD width="25%"&gt;Splunk&lt;/TD&gt;&lt;TD width="12.5%"&gt;estreamer TA&lt;/TD&gt;&lt;TD width="6.25%"&gt;customizations if any&lt;/TD&gt;&lt;TD width="6.25%"&gt;Status&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="26.01010101010101%"&gt;6.6.4&lt;/TD&gt;&lt;TD width="23.98989898989899%"&gt;18.04.5 LTS&lt;/TD&gt;&lt;TD width="25%"&gt;7.2.10&lt;/TD&gt;&lt;TD width="12.5%"&gt;3.6.8&lt;/TD&gt;&lt;TD width="6.25%"&gt;default sourcetype&lt;/TD&gt;&lt;TD width="6.25%"&gt;Stable&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 18:44:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557662#M92293</guid>
      <dc:creator>elee_splunk</dc:creator>
      <dc:date>2021-06-29T18:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557697#M92298</link>
      <description>&lt;P&gt;Please email a link to this thread to &lt;A href="mailto:encore-community@cisco.com" target="_blank"&gt;encore-community@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Doug&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 20:56:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557697#M92298</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2021-06-29T20:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557776#M92309</link>
      <description>&lt;P&gt;Just did,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 09:51:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557776#M92309</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-30T09:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557777#M92310</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235641"&gt;@elee_splunk&lt;/a&gt;&amp;nbsp; That's good to hear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appears Python 2 script seems to offer stability in your case. In our environment, it's a bit puzzling in the fact that we have one forwarder ingesting logs without issues in the new version while the prod environment seems to throw errors.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 09:53:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557777#M92310</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-30T09:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557843#M92317</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We believe this is a bug in the splencore.sh script, specifically with the clean command, in a prior update we modified the location of the ingest directory,&amp;nbsp; this script was not updated to reflect the new location which we believe is causing the error you are seeing.&amp;nbsp; Please perform the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; Disable the clean script&lt;/P&gt;&lt;P&gt;2) Modify the splencore.sh to point the proper ingest directory&lt;/P&gt;&lt;P&gt;3) Upgrade the TA to 4.6.1, which includes the modification above&lt;/P&gt;&lt;P&gt;If problems continue please open a ticket with TAC support so we can collect additional trouble shoot files&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seyed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 15:22:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557843#M92317</guid>
      <dc:creator>skhademd</dc:creator>
      <dc:date>2021-06-30T15:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557848#M92320</link>
      <description>&lt;P&gt;Will try that. I don't believe we have access to the 4.6.1 version of the TA yet. Doesn't look like it's published to splunkbase.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 15:27:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557848#M92320</guid>
      <dc:creator>elee_splunk</dc:creator>
      <dc:date>2021-06-30T15:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557851#M92322</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235961"&gt;@skhademd&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The new TA is available now. Will validate and confirm.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 16:10:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557851#M92322</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-30T16:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557895#M92326</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235961"&gt;@skhademd&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have installed 4.6.1 afresh and configured from scratch to connect to our FMCs(with DEBUG logging enabled. Collection has resumed in Splunk. However, here are the initial observations.&lt;/P&gt;&lt;P&gt;1)Data collection is always 10-15 minutes behind current time.&lt;/P&gt;&lt;P&gt;2)Checking estreamer logs, the events per second is consistently on the decrease. Not sure if it's on the path to stoppage of collection&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-06-30 14:19:58,631 Monitor INFO Running. 103400 handled; average rate 25.34 ev/sec;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:20:08,633 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:20:23,145 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:20:33,658 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:20:47,175 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:20:57,684 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:08,190 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:18,699 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:29,209 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:36,240 Receiver DEBUG Got null message.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:47,252 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:57,764 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:21:58,274 Monitor INFO Running. 103400 handled; average rate 24.62 ev/sec;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:22:08,267 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:22:18,778 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:22:29,289 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:22:36,301 Receiver DEBUG Got null message.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:22:46,312 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:22:56,822 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:23:14,347 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:23:29,368 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:23:43,386 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:23:47,402 Monitor INFO Running. 103400 handled; average rate 23.93 ev/sec;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:23:57,406 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:24:07,915 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:24:22,436 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:24:32,946 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:24:43,454 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:24:53,959 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:04,471 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:11,492 Receiver DEBUG Got null message.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:21,498 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:32,006 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:42,518 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:53,028 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:25:53,542 Monitor INFO Running. 103400 handled; average rate 23.29 ev/sec;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:26:03,540 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:26:11,564 Receiver DEBUG Got null message.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:26:21,563 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:26:32,076 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:26:42,584 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:26:53,089 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:27:03,601 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:27:11,626 Receiver DEBUG Got null message.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:27:21,636 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:27:32,149 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:27:49,673 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:28:00,183 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:28:00,697 Monitor INFO Running. 103400 handled; average rate 22.67 ev/sec;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:28:10,688 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:28:21,193 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-06-30 14:28:31,701 Receiver DEBUG FMC sent no data&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3)Clean up script has an issue with absolute vs relative path I suspect , as I notice this error in Splunk internal logs.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;06-30-2021 14:17:27.087 -0400 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/TA-eStreamer/bin/splencore.sh clean" find: `./encore/data': No such file or directory&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 18:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/557895#M92326</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-06-30T18:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/558007#M92334</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235961"&gt;@skhademd&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/92818"&gt;@douglashurd&lt;/a&gt;&amp;nbsp;Unfortunately, the new version of 4.6.1 didn't help either. The same error is back, as always, slightly later in the same day.&lt;/P&gt;&lt;P&gt;In parallel, we have had our Network admins raise a ticket with Cisco. Cisco has acknowledged the problem and raised a bug as can be seen below. I will e-mail details of the case to the e-mail address shared by Doug.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a bug open for this, but it looks like there is no root cause found yet:&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy79722" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy79722&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Logs as shown below.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2021-06-30 18:21:51,735 Monitor INFO Running. 104600 handled; average rate 5.62 ev/sec;&lt;BR /&gt;2021-06-30 18:22:19,262 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:22:41,791 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:22:52,297 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:23:02,798 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:23:13,307 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:23:23,836 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:23:34,343 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:23:52,872 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:23:53,384 Monitor INFO Running. 104600 handled; average rate 5.59 ev/sec;&lt;BR /&gt;2021-06-30 18:24:11,898 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:24:22,400 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:24:32,907 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:24:43,413 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:24:53,929 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:25:00,952 Receiver DEBUG Got null message.&lt;BR /&gt;2021-06-30 18:25:15,971 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:25:26,472 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:25:45,003 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:25:51,028 Monitor INFO Running. 104700 handled; average rate 5.56 ev/sec;&lt;BR /&gt;2021-06-30 18:26:11,040 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:26:21,550 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:26:32,058 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:26:42,569 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:26:53,076 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:27:00,099 Receiver DEBUG Got null message.&lt;BR /&gt;2021-06-30 18:27:10,099 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:27:20,612 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:27:31,123 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:27:41,635 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:27:46,163 Monitor INFO Running. 104700 handled; average rate 5.52 ev/sec;&lt;BR /&gt;2021-06-30 18:27:56,154 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:28:10,174 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:28:25,192 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:28:41,212 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:29:05,236 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:29:15,746 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:29:32,268 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:29:45,291 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:29:55,802 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:29:56,312 Monitor INFO Running. 104700 handled; average rate 5.49 ev/sec;&lt;BR /&gt;2021-06-30 18:30:06,304 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:30:17,330 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:30:34,346 Receiver DEBUG FMC sent no data&lt;BR /&gt;2021-06-30 18:30:47,081 Service ERROR [no message or attrs]: Invalid JSON in settings file&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 08:15:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/558007#M92334</guid>
      <dc:creator>vik_splunk</dc:creator>
      <dc:date>2021-07-01T08:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Encore data ingestion issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/558030#M92338</link>
      <description>&lt;P&gt;I compared the new 4.6.1 version and for me issue is also not fixed. The changes necessary for the cleaning to run, I already implemented before.&lt;/P&gt;&lt;P&gt;For now I added another script input to call splencore.sh with a stop statement every x hours, so the service gets restarted regularly. The error appears after random time.&amp;nbsp; Last time error appeared&amp;nbsp; after 45 minutes, but the time before it was running more than 10 hours.&lt;BR /&gt;And still same behavior, logging continues to work after the error is logged but stops some time later.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 13:53:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcefire-Encore-data-ingestion-issue/m-p/558030#M92338</guid>
      <dc:creator>AlexS</dc:creator>
      <dc:date>2021-07-01T13:53:57Z</dc:date>
    </item>
  </channel>
</rss>

