All Apps and Add-ons

TA-pfsense logs start then... stop

j_stock
Explorer

I have a weird issue with the TA-pfsense TA.

I can get logs in for about half a second and then they just mysteriously stop.

A packet trace shows the logs are still being sent and the port is remaining open.

splunkd.log has something interesting though:

01-12-2020 17:25:30.970 +0800 WARN DateParserVerbose - A possible timestamp match (Sun Sep 9 09:48:25 2001) is outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: source=udp:5016|host=pfsense_hostname|pfsense|

Any ideas please?

0 Karma
1 Solution

j_stock
Explorer
0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...