All Apps and Add-ons

Not getting feeds from the minemeld?

shiboo
Loves-to-Learn Lots

Hi Team,

We are not getting logs from the minemeld. Getting below logs.

07-15-2020 06:07:24.917 -0400 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/Splunk_TA_paloalto/bin/minemeld_feed.py" ERRORHTTPSConnectionPool(host='127.0.0.1', port=8089): Max retries exceeded with url: /servicesNS/nobody/Splunk_TA_paloalto/storage/collections/data/minemeldfeeds?query=%7B%22splunk_source%22%3A+%22Mine_Meld%22%7D (Caused by ReadTimeoutError("HTTPSConnectionPool(host='127.0.0.1', port=8089): Read timed out. (read timeout=30.0)",))


07-15-2020 06:12:24.843 -0400 WARN DateParserVerbose - Failed to parse timestamp in first MAX_TIMESTAMP_LOOKAHEAD (128) characters of event. Defaulting to timestamp of previous event (Wed Jul 15 06:12:24 2020). Context: source=/opt/splunk/var/log/splunk/Splunk_TA_paloalto_minemeld_feed.log|host=ndcsecspkhfp51.global.loc|Splunk_TA_paloalto_minemeld_feed-too_small|730457

 

 

Labels (1)
0 Karma

MK-DRT
Loves-to-Learn Lots

did you end up finding a solution?

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...