<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco eStreamer encore 8.1.2 Data Ingestion Issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-eStreamer-encore-8-1-2-Data-Ingestion-Issue/m-p/576086#M101807</link>
    <description>&lt;P&gt;The inputs.conf had the stanza pointing to the wrong directory, also sourcetype name was missing after the upgrade. Had to connect the path and add the sourcetype name to fix&lt;/P&gt;</description>
    <pubDate>Tue, 23 Nov 2021 20:58:58 GMT</pubDate>
    <dc:creator>km1986</dc:creator>
    <dc:date>2021-11-23T20:58:58Z</dc:date>
    <item>
      <title>Cisco eStreamer encore 8.1.2 Data Ingestion Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-eStreamer-encore-8-1-2-Data-Ingestion-Issue/m-p/574518#M101559</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi All, I have recently upgraded Splunk HF from 7.3.x to 8.1.2 and also the Cisco eStreamer (Encore) app from 3.6.x to 4.8.1. Both upgrades went fine and cisco:estreamer:data logs were coming in fine till 1.5 hours post-upgrade after which logs stopped coming in. The file&amp;nbsp; estreamer.log in /opt/splunk/etc/apps/TA-eStreamer/bin/encore doest show any ERROR ( INFO&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Running. 3500 handled; average rate 4.86 ev/sec;). Also, I'm able to see logs populating in /opt/splunk/etc/apps/TA-eStreamer/data. However, it appears logs are not getting updated in cisco:estreamer:data sourcetype. There are other log sources relayed from the HF to cloud which do not have any issues (ruled out any network connectivity issues between HF and splunkcloud). Has anyone else seen similar issues?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 04:28:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-eStreamer-encore-8-1-2-Data-Ingestion-Issue/m-p/574518#M101559</guid>
      <dc:creator>km1986</dc:creator>
      <dc:date>2021-11-11T04:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer encore 8.1.2 Data Ingestion Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-eStreamer-encore-8-1-2-Data-Ingestion-Issue/m-p/576086#M101807</link>
      <description>&lt;P&gt;The inputs.conf had the stanza pointing to the wrong directory, also sourcetype name was missing after the upgrade. Had to connect the path and add the sourcetype name to fix&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 20:58:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-eStreamer-encore-8-1-2-Data-Ingestion-Issue/m-p/576086#M101807</guid>
      <dc:creator>km1986</dc:creator>
      <dc:date>2021-11-23T20:58:58Z</dc:date>
    </item>
  </channel>
</rss>

