<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OSSEC and SPLUNK... just stopped ? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/OSSEC-and-SPLUNK-just-stopped/m-p/15765#M6749</link>
    <description>&lt;P&gt;I've had both services running on the save Ubuntu 10.04 server for about a week.  OSSEC is cooking along gathering information.  And SPLUNK is happily displaying this data for easy quick high level viewing.&lt;/P&gt;

&lt;P&gt;I did switch SPLUNK to the "free" license.&lt;/P&gt;

&lt;P&gt;For days &amp;amp; days I've had good data. @ around noon yesterday, it started to taper DOWN...&lt;/P&gt;

&lt;P&gt;06-18-2010 05:59:55.073 INFO  Metrics - group=per_source_thruput, series="udp:10002", kbps=2.371535, eps=3.741935, kb=73.517578
host=lcua141   Options|  sourcetype=splunkd   Options|  source=/opt/splunk/var/log/splunk/metrics.log   Options&lt;/P&gt;

&lt;P&gt;I noticed today @ 6am data stopped.  This was the last entry... &lt;/P&gt;

&lt;P&gt;6/18/10
6:00:26.048 AM&lt;BR /&gt;
06-18-2010 06:00:26.048 INFO  Metrics - group=per_source_thruput, series="udp:10002", kbps=2.371220, eps=4.258065, kb=73.507812
host=lcua141   Options|  sourcetype=splunkd   Options|  source=/opt/splunk/var/log/splunk/metrics.log   Options&lt;/P&gt;

&lt;P&gt;I'll start by looking at this splunk log... &lt;/P&gt;

&lt;P&gt;Any suggestions/ideas appreciated!&lt;/P&gt;

&lt;P&gt;Thank you! &lt;/P&gt;

&lt;P&gt;JLH &lt;/P&gt;</description>
    <pubDate>Fri, 18 Jun 2010 21:32:47 GMT</pubDate>
    <dc:creator>jhuebner</dc:creator>
    <dc:date>2010-06-18T21:32:47Z</dc:date>
    <item>
      <title>OSSEC and SPLUNK... just stopped ?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/OSSEC-and-SPLUNK-just-stopped/m-p/15765#M6749</link>
      <description>&lt;P&gt;I've had both services running on the save Ubuntu 10.04 server for about a week.  OSSEC is cooking along gathering information.  And SPLUNK is happily displaying this data for easy quick high level viewing.&lt;/P&gt;

&lt;P&gt;I did switch SPLUNK to the "free" license.&lt;/P&gt;

&lt;P&gt;For days &amp;amp; days I've had good data. @ around noon yesterday, it started to taper DOWN...&lt;/P&gt;

&lt;P&gt;06-18-2010 05:59:55.073 INFO  Metrics - group=per_source_thruput, series="udp:10002", kbps=2.371535, eps=3.741935, kb=73.517578
host=lcua141   Options|  sourcetype=splunkd   Options|  source=/opt/splunk/var/log/splunk/metrics.log   Options&lt;/P&gt;

&lt;P&gt;I noticed today @ 6am data stopped.  This was the last entry... &lt;/P&gt;

&lt;P&gt;6/18/10
6:00:26.048 AM&lt;BR /&gt;
06-18-2010 06:00:26.048 INFO  Metrics - group=per_source_thruput, series="udp:10002", kbps=2.371220, eps=4.258065, kb=73.507812
host=lcua141   Options|  sourcetype=splunkd   Options|  source=/opt/splunk/var/log/splunk/metrics.log   Options&lt;/P&gt;

&lt;P&gt;I'll start by looking at this splunk log... &lt;/P&gt;

&lt;P&gt;Any suggestions/ideas appreciated!&lt;/P&gt;

&lt;P&gt;Thank you! &lt;/P&gt;

&lt;P&gt;JLH &lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2010 21:32:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/OSSEC-and-SPLUNK-just-stopped/m-p/15765#M6749</guid>
      <dc:creator>jhuebner</dc:creator>
      <dc:date>2010-06-18T21:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: OSSEC and SPLUNK... just stopped ?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/OSSEC-and-SPLUNK-just-stopped/m-p/15766#M6750</link>
      <description>&lt;P&gt;I got this going by running a re-install.  apparently something got mad, but the reinstall fixed it.&lt;/P&gt;

&lt;P&gt;JLH &lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2010 00:48:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/OSSEC-and-SPLUNK-just-stopped/m-p/15766#M6750</guid>
      <dc:creator>jhuebner</dc:creator>
      <dc:date>2010-10-21T00:48:00Z</dc:date>
    </item>
  </channel>
</rss>

