We are also facing the same error messages when configuring the deploy server. We have deployed the universal forwarder 9.4.4 via rpm on docker container. Error: tcp_conn_open_afux ossocket_connect failed with No such file or directory How did you fix the error ? Any configuration changes needed ?
... View more
I used to schedule the report on 1st day of month @00:00 to retrieve the annual reports from Jan 1 to last day of prev month. This approach works perfect for first 11 months whereas for Dec month (say Dec2016) it will not work because earliest=@y will take next year (2017) if it runs on 1st day of Jan2017.
How do I handle this? Can the earliest field be modified if month is Dec using any eval conditions?
... View more
Hi,
I have created a search to pull annual records using time range "Year to date" option. It displays the all the annual records perfectly. If I save this search as an alert and scheduled to run on certain days, it's not fetching "Year to date" records instead it gives records for last 1 month. So how do I create an alert to pull "Year to date" records ?
... View more