- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

svclee
Engager
07-27-2015
02:52 PM
I have installed the v3.0 app on my Splunk indexer and when going to the APP to make a new connection, I get the below pop-up every time:
Reconnecting to Splunk server
Your network connection may have been lost or Splunk server may be down.
Is there a fix to this?
I have manually created a connection, but does not seem to be pulling logs.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

svclee
Engager
09-28-2015
08:49 AM
I have misconfigured the the sic entity name.
Once we ran the lea debug, and found the right sic name, we updated the opsec.conf then restarted.
After restarting, all events are now available for search
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

svclee
Engager
09-28-2015
08:49 AM
I have misconfigured the the sic entity name.
Once we ran the lea debug, and found the right sic name, we updated the opsec.conf then restarted.
After restarting, all events are now available for search
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

jcoates_splunk

Splunk Employee
09-26-2015
01:35 PM
what does it say when you look at the logs?
index=_internal source=*Splunk_TA_opseclea*
