<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Estreamer failing after Splunk 8.1.1 upgrade in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Estreamer-failing-after-Splunk-8-1-1-upgrade/m-p/546197#M90986</link>
    <description>&lt;P&gt;Yes, the devs ended up fixing it in the latest version of the add on&lt;/P&gt;</description>
    <pubDate>Wed, 31 Mar 2021 11:43:01 GMT</pubDate>
    <dc:creator>rpoiri101</dc:creator>
    <dc:date>2021-03-31T11:43:01Z</dc:date>
    <item>
      <title>Cisco Estreamer failing after Splunk 8.1.1 upgrade</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Estreamer-failing-after-Splunk-8-1-1-upgrade/m-p/539227#M90339</link>
      <description>&lt;P&gt;I'm running a heavy forwarder on Redhat which I recently upgraded to Splunk Enterprise 8.1.1. Most apps survived the upgrade without issue. The Splunk estreamer app (&lt;A href="https://splunkbase.splunk.com/app/3662/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3662/&lt;/A&gt;) however, doesn't seem to be working anymore. It works for a little while, but then I get the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN class="t"&gt;Monitor&lt;/SPAN&gt; &lt;SPAN class="t h"&gt;ERROR&lt;/SPAN&gt; [&lt;SPAN class="t"&gt;no&lt;/SPAN&gt; &lt;SPAN class="t"&gt;message&lt;/SPAN&gt; &lt;SPAN class="t"&gt;or&lt;/SPAN&gt; &lt;SPAN class="t"&gt;attrs&lt;/SPAN&gt;]&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ProxyProcess&lt;/SPAN&gt;[&lt;SPAN class="t"&gt;name=subscriberParser&lt;/SPAN&gt;]&lt;SPAN class="t"&gt;.request&lt;/SPAN&gt;(&lt;SPAN class="t"&gt;status&lt;/SPAN&gt;) &lt;SPAN class="t"&gt;timeout&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;This is often appears soon after this:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;ERROR&lt;/SPAN&gt;&lt;/SPAN&gt; [&lt;SPAN class="t"&gt;no&lt;/SPAN&gt; &lt;SPAN class="t"&gt;message&lt;/SPAN&gt; &lt;SPAN class="t"&gt;or&lt;/SPAN&gt; &lt;SPAN class="t"&gt;attrs&lt;/SPAN&gt;]&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;View&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;object&lt;/SPAN&gt; &lt;SPAN class="t"&gt;has&lt;/SPAN&gt; &lt;SPAN class="t"&gt;no&lt;/SPAN&gt; &lt;SPAN class="t"&gt;attribute&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;_View__isHex&lt;/SPAN&gt;'&lt;SPAN class="t"&gt;\n&lt;/SPAN&gt;'&lt;SPAN class="t"&gt;View&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;object&lt;/SPAN&gt; &lt;SPAN class="t"&gt;has&lt;/SPAN&gt; &lt;SPAN class="t"&gt;no&lt;/SPAN&gt; &lt;SPAN class="t"&gt;attribute&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;_View__isHex&lt;/SPAN&gt;'&lt;SPAN class="t"&gt;Traceback&lt;/SPAN&gt; (&lt;SPAN class="t"&gt;most&lt;/SPAN&gt; &lt;SPAN class="t"&gt;recent&lt;/SPAN&gt; &lt;SPAN class="t"&gt;call&lt;/SPAN&gt; &lt;SPAN class="t"&gt;last&lt;/SPAN&gt;)&lt;SPAN class="t"&gt;:\n&lt;/SPAN&gt; &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/baseproc.py&lt;/SPAN&gt;", &lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;209&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;receiveInput\n&lt;/SPAN&gt; &lt;SPAN class="t"&gt;self.onReceive&lt;/SPAN&gt;( &lt;SPAN class="t"&gt;item&lt;/SPAN&gt; )&lt;SPAN class="t"&gt;\n&lt;/SPAN&gt; &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/pipeline.py&lt;/SPAN&gt;", &lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;350&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;onReceive\n&lt;/SPAN&gt; &lt;SPAN class="t"&gt;_do&lt;/SPAN&gt;( &lt;SPAN class="t"&gt;items&lt;/SPAN&gt; )&lt;SPAN class="t"&gt;\n&lt;/SPAN&gt; &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/pipeline.py&lt;/SPAN&gt;", &lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;344&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;_do\n&lt;/SPAN&gt; &lt;SPAN class="t"&gt;self.onEvent&lt;/SPAN&gt;( &lt;SPAN class="t"&gt;item&lt;/SPAN&gt; )&lt;SPAN class="t"&gt;\n&lt;/SPAN&gt; &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/pipeline.py&lt;/SPAN&gt;", &lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;338&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;onEvent\n&lt;/SPAN&gt; &lt;SPAN class="t"&gt;decorate&lt;/SPAN&gt;( &lt;SPAN class="t"&gt;item&lt;/SPAN&gt;['&lt;SPAN class="t"&gt;record&lt;/SPAN&gt;'], &lt;SPAN class="t"&gt;self.settings&lt;/SPAN&gt; )&lt;SPAN class="t"&gt;\n&lt;/SPAN&gt; &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/pipeline.py&lt;/SPAN&gt;", &lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;185&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;decorate\n&lt;/SPAN&gt; &lt;SPAN class="t"&gt;settings.cache&lt;/SPAN&gt;(), &lt;SPAN class="t"&gt;record&lt;/SPAN&gt; )&lt;SPAN class="t"&gt;.create&lt;/SPAN&gt;()&lt;SPAN class="t"&gt;\n&lt;/SPAN&gt; &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/metadata/view.py&lt;/SPAN&gt;", &lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;532&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;create\n&lt;/SPAN&gt; &lt;SPAN class="t"&gt;if&lt;/SPAN&gt;(&lt;SPAN class="t"&gt;self.__isHex&lt;/SPAN&gt;(&lt;SPAN class="t"&gt;hex32&lt;/SPAN&gt;)) &lt;SPAN class="t"&gt;:\nAttributeError:&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;View&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;object&lt;/SPAN&gt; &lt;SPAN class="t"&gt;has&lt;/SPAN&gt; &lt;SPAN class="t"&gt;no&lt;/SPAN&gt; &lt;SPAN class="t"&gt;attribute&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;_View__isHex&lt;/SPAN&gt;'&lt;SPAN class="t"&gt;\n&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I've tried downloading the latest version of the app, no change. To get it working again, I have to disable the 3 scripts that bring in the data, kill the PID's running the estreamer, then re-enable the scripts. Sometimes it works again for a few hours. Sometimes a few minutes. Any suggestions?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, something worth mentioning: I noticed when I go to manage apps, there's no "set up" option for this add on or the firepower splunk app, which is normally where I'd do the config for this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 23:31:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Estreamer-failing-after-Splunk-8-1-1-upgrade/m-p/539227#M90339</guid>
      <dc:creator>rpoiri101</dc:creator>
      <dc:date>2021-02-09T23:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Estreamer failing after Splunk 8.1.1 upgrade</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Estreamer-failing-after-Splunk-8-1-1-upgrade/m-p/546130#M90977</link>
      <description>&lt;P&gt;I have the same problem with Splunk version 8.0.2&lt;/P&gt;&lt;P&gt;Did you solve this problem?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 06:00:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Estreamer-failing-after-Splunk-8-1-1-upgrade/m-p/546130#M90977</guid>
      <dc:creator>src_pwn3d</dc:creator>
      <dc:date>2021-03-31T06:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Estreamer failing after Splunk 8.1.1 upgrade</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Estreamer-failing-after-Splunk-8-1-1-upgrade/m-p/546197#M90986</link>
      <description>&lt;P&gt;Yes, the devs ended up fixing it in the latest version of the add on&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 11:43:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Estreamer-failing-after-Splunk-8-1-1-upgrade/m-p/546197#M90986</guid>
      <dc:creator>rpoiri101</dc:creator>
      <dc:date>2021-03-31T11:43:01Z</dc:date>
    </item>
  </channel>
</rss>

