Manually Reset the Splunk Application for Data Collection
book
Article ID: 227378
calendar_today
Updated On:
Products
Email Security.cloud
Issue/Introduction
A noticeable lag when it comes to data feed collection. Generate a new cookie for the Email Security Cloud Splunk Application.
Environment
Email Security.Cloud Splunk TA add-on
Resolution
Instructions to manually reset Splunk App:
- Log into your Splunk instance
- In the Splunk UI navigate to “Settings > Data > Data inputs”
- Under “Local inputs” select “Scripts”
- In the “Filter” search box, search for “symantec_collect_atp.py”
- Under the “Status” column of “symantec_collect_atp.py” click “Disable”
- Navigate to the following file location:
- Windows: C:\Program Files\Splunk\etc\apps\TA-symantec_email\local\
- *nix: $SPLUNK_HOME/etc/apps/TA-symantec_email/local/
- Open the file “symantec_email_setup.conf”
- Change the following variables:
- enable_force_reset parameter = True
- force_reset_timestamp = <timestamp> (Note: Enter <timestamp> in yyyy-MM-ddTHH:mm:ssZ format.)
- Go back to the Splunk UI and follow steps 1-4 to re-enable “symantec_collect_atp.py” by clicking “Enable” under the “Status” column.
Note: With the steps provided, a possibility of duplicate entries can happen especially going beyond the time the feed was functioning properly.
Feedback
thumb_up
Yes
thumb_down
No