@dgillette3 I am getting some warning logs yes. I am getting connection aborted - connected reset by peer.
Then I got this error. For some reason my Digicert Log isn't pulling any events.
2019-06-12 10:11:46,605 ERROR pid=12311 tid=MainThread file=base_modinput.py:log_error:307 | Get error when collecting events.
Traceback (most recent call last):
File "/opt/splunk/etc/apps/TA-ct-log/bin/ta_ct_log/modinput_wrapper/base_modinput.py", line 127, in stream_events
self.collect_events(ew)
File "/opt/splunk/etc/apps/TA-ct-log/bin/ct_log.py", line 64, in collect_events
input_module.collect_events(self, ew)
File "/opt/splunk/etc/apps/TA-ct-log/bin/input_module_ct_log.py", line 26, in collect_events
obj.process_log()
File "/opt/splunk/etc/apps/TA-ct-log/bin/ctl/ctl2splunk.py", line 214, in process_log
leaf_inputs = self.get_entries(i, i+fetch_size-1)
File "/opt/splunk/etc/apps/TA-ct-log/bin/ctl/ctl2splunk.py", line 148, in get_entries
self.helper.log_error("get_entries: %s, status %s, %s" % (r.url, r.status_code, str(e)))
UnboundLocalError: local variable 'r' referenced before assignment
So I'm not getting any events from that log. Trying to find a domain certificate that we own and it says it's listed in like 4 or 5 different logs and has a serial number and ID but I can't find it within the Splunk search.
... View more