<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: s4cs Fallback error in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/s4cs-Fallback-error/m-p/748262#M118914</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310974"&gt;@Bedrohungsjäger&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please can I check what port configuration you have in SC4S? Have you set your port with&amp;nbsp;&lt;SPAN&gt;SC4S_LISTEN_ZSCALER_LSS_TCP_PORT ? (For more info on setup please see&amp;nbsp;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/1.90.1/sources/Zscaler/" target="_blank"&gt;https://splunk.github.io/splunk-connect-for-syslog/1.90.1/sources/Zscaler/&lt;/A&gt;&amp;nbsp;but you may have already seen this!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jun 2025 17:33:47 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-06-18T17:33:47Z</dc:date>
    <item>
      <title>s4cs Fallback error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/s4cs-Fallback-error/m-p/748257#M118912</link>
      <description>&lt;P&gt;Hey Folkes&lt;BR /&gt;&lt;BR /&gt;Ingesting ZPA logs in Splunk using the Zscaler LSS service, I believe the configuration is correct based on the documentation, however the sourcetype is coming up as sc4s fallback and the logs are unreadable.&lt;BR /&gt;&lt;BR /&gt;It's confirmed that the logs are streaming to the HF.&lt;BR /&gt;&lt;BR /&gt;Can anyone who've done a similar configuration setup advise?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 17:04:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/s4cs-Fallback-error/m-p/748257#M118912</guid>
      <dc:creator>Bedrohungsjäger</dc:creator>
      <dc:date>2025-06-18T17:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: s4cs Fallback error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/s4cs-Fallback-error/m-p/748258#M118913</link>
      <description>&lt;P&gt;SC4S and not S4cs, apologies for the typo.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 17:05:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/s4cs-Fallback-error/m-p/748258#M118913</guid>
      <dc:creator>Bedrohungsjäger</dc:creator>
      <dc:date>2025-06-18T17:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: s4cs Fallback error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/s4cs-Fallback-error/m-p/748262#M118914</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310974"&gt;@Bedrohungsjäger&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please can I check what port configuration you have in SC4S? Have you set your port with&amp;nbsp;&lt;SPAN&gt;SC4S_LISTEN_ZSCALER_LSS_TCP_PORT ? (For more info on setup please see&amp;nbsp;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/1.90.1/sources/Zscaler/" target="_blank"&gt;https://splunk.github.io/splunk-connect-for-syslog/1.90.1/sources/Zscaler/&lt;/A&gt;&amp;nbsp;but you may have already seen this!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 17:33:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/s4cs-Fallback-error/m-p/748262#M118914</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-18T17:33:47Z</dc:date>
    </item>
  </channel>
</rss>

