I keep seeing this or similar issues but have yet to find an answer. I have 2 ASAs forwarding their logs. I can search for one and find log data but the not the other one. I search thru metrics.log, license_usage.log, and splunkd.log. I find data about both of them in metrics and license, but only the one that works in splunkd.log. I find errors about events with no timestamp. And for both ASAs the license_usage.log file shows the same idx="xxxx" string.
So I am confused as to why I can't find any events for the second ASA.
... View more