I have a weird issue with the TA-pfsense TA.
I can get logs in for about half a second and then they just mysteriously stop.
A packet trace shows the logs are still being sent and the port is remaining open.
splunkd.log has something interesting though:
01-12-2020 17:25:30.970 +0800 WARN DateParserVerbose - A possible timestamp match (Sun Sep 9 09:48:25 2001) is outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: source=udp:5016|host=pfsense_hostname|pfsense|
Any ideas please?
Okay, the answer is this:
https://answers.splunk.com/answers/626816/pfsense-event-date-time-wrong.html
Okay, the answer is this:
https://answers.splunk.com/answers/626816/pfsense-event-date-time-wrong.html