I have 3 sensors, 2 of which are remote. I installed and configured the IPS add-on and it will successfully retrieve events from all of the sensors. The problem is, after that first event query, it does not retrieve any more events from the remote sensors until I restart splunk (or perhaps the IPS add-on; I'm new to all of this.)
Is there some way to increase the time between queries? As I understand the interval= setting, 1 should automatically retry 1 second after the previous query exits.
I can't tell if that means "successfully exits."
When I check the logs for SDEE errors I'm seeing "connection reset by peer" errors, which due to the nature of the circuit I am unlikely to be able to change, but I would still think at some point the splunk add-on would just keep trying and that does not seem to be the case.
Any help would be greatly appreciated.
... View more