<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sawmill 7.3.1 DB rebuild fails due to corrupt date fields in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/sawmill-7-3-1-db-rebuild-fails-due-to-corrupt-date-fields/m-p/1323102#M882</link>
    <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;anybody able to help? My new Sawmill 7.3.1 installation (Windows x86) fails to rebuild the database. It never worked, the "background process stopped unexpectedly". Logs are default standard Squid format access logs from a S160 (v5.6.6). Profile is standard "HR" with the log format automatically recognized by Sawmill. "Sec Ops" profile yields the same errors.&lt;BR /&gt;&lt;BR /&gt;When performing a command-line rebuild with debug outputs, it looks like on none of the log entries the date/time can be recognized (same error for all records).&lt;BR /&gt;&lt;BR /&gt;[t2]: [p]: Processing line: [t2]: 1255880992.122 0 10.70.10.18 TCP_DENIED/407 242 HEAD &lt;A href="http://osce8-p.activeupdate.trendmicro.com/activeupdate/ini_xml.zip" target="_blank"&gt;http://osce8-p.activeupdate.trendmicro.com/activeupdate/ini_xml.zip&lt;/A&gt; - NONE/- - OTHER-NONE &amp;amp;lt;Comp,-,-,-,-,-,-,-,-,-,-,-,-&amp;amp;gt; -&lt;BR /&gt;[t2]: [p]: Got log token[t2]:  '1255880992.122' (index=1, subindex=1)&lt;BR /&gt;[t2]: [p]: Got normalized date from date field: {corrupt}&lt;BR /&gt;[t2]: [p]: Got normalized time from time field: {corrupt}&lt;BR /&gt;&lt;BR /&gt;The log entry reads&lt;BR /&gt;1255880992.122 0 10.70.10.18 TCP_DENIED/407 242 HEAD &lt;A href="http://osce8-p.activeupdate.trendmicro.com/activeupdate/ini_xml.zip" target="_blank"&gt;http://osce8-p.activeupdate.trendmicro.com/activeupdate/ini_xml.zip&lt;/A&gt; - NONE/- - OTHER-NONE &amp;amp;lt;Comp,-,-,-,-,-,-,-,-,-,-,-,-&amp;amp;gt; -&lt;BR /&gt;&lt;BR /&gt;How can the log data be imported successfully? Do I need to change the access log file format on the S160?&lt;BR /&gt;&lt;BR /&gt;Any help will be appreciated.&lt;BR /&gt;&lt;BR /&gt;Kind regards&lt;BR /&gt;&lt;BR /&gt;Frederik&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2009 18:08:00 GMT</pubDate>
    <dc:creator>fanheuser_ironport</dc:creator>
    <dc:date>2009-10-28T18:08:00Z</dc:date>
    <item>
      <title>Sawmill 7.3.1 DB rebuild fails due to corrupt date fields</title>
      <link>https://community.cisco.com/t5/web-security/sawmill-7-3-1-db-rebuild-fails-due-to-corrupt-date-fields/m-p/1323102#M882</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;anybody able to help? My new Sawmill 7.3.1 installation (Windows x86) fails to rebuild the database. It never worked, the "background process stopped unexpectedly". Logs are default standard Squid format access logs from a S160 (v5.6.6). Profile is standard "HR" with the log format automatically recognized by Sawmill. "Sec Ops" profile yields the same errors.&lt;BR /&gt;&lt;BR /&gt;When performing a command-line rebuild with debug outputs, it looks like on none of the log entries the date/time can be recognized (same error for all records).&lt;BR /&gt;&lt;BR /&gt;[t2]: [p]: Processing line: [t2]: 1255880992.122 0 10.70.10.18 TCP_DENIED/407 242 HEAD &lt;A href="http://osce8-p.activeupdate.trendmicro.com/activeupdate/ini_xml.zip" target="_blank"&gt;http://osce8-p.activeupdate.trendmicro.com/activeupdate/ini_xml.zip&lt;/A&gt; - NONE/- - OTHER-NONE &amp;amp;lt;Comp,-,-,-,-,-,-,-,-,-,-,-,-&amp;amp;gt; -&lt;BR /&gt;[t2]: [p]: Got log token[t2]:  '1255880992.122' (index=1, subindex=1)&lt;BR /&gt;[t2]: [p]: Got normalized date from date field: {corrupt}&lt;BR /&gt;[t2]: [p]: Got normalized time from time field: {corrupt}&lt;BR /&gt;&lt;BR /&gt;The log entry reads&lt;BR /&gt;1255880992.122 0 10.70.10.18 TCP_DENIED/407 242 HEAD &lt;A href="http://osce8-p.activeupdate.trendmicro.com/activeupdate/ini_xml.zip" target="_blank"&gt;http://osce8-p.activeupdate.trendmicro.com/activeupdate/ini_xml.zip&lt;/A&gt; - NONE/- - OTHER-NONE &amp;amp;lt;Comp,-,-,-,-,-,-,-,-,-,-,-,-&amp;amp;gt; -&lt;BR /&gt;&lt;BR /&gt;How can the log data be imported successfully? Do I need to change the access log file format on the S160?&lt;BR /&gt;&lt;BR /&gt;Any help will be appreciated.&lt;BR /&gt;&lt;BR /&gt;Kind regards&lt;BR /&gt;&lt;BR /&gt;Frederik&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2009 18:08:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/sawmill-7-3-1-db-rebuild-fails-due-to-corrupt-date-fields/m-p/1323102#M882</guid>
      <dc:creator>fanheuser_ironport</dc:creator>
      <dc:date>2009-10-28T18:08:00Z</dc:date>
    </item>
    <item>
      <title>Solved: Sawmill 7.3.1 DB rebuild fails</title>
      <link>https://community.cisco.com/t5/web-security/sawmill-7-3-1-db-rebuild-fails-due-to-corrupt-date-fields/m-p/1323103#M883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;the problem has been solved: the log files got corrupted during transfer from the WSA to the Sawmill server. With uncorrupted logfiles, database rebuild worked as expected.&lt;BR /&gt;&lt;BR /&gt;Hooray!&lt;BR /&gt;&lt;BR /&gt;Frederik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Oct 2009 22:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/sawmill-7-3-1-db-rebuild-fails-due-to-corrupt-date-fields/m-p/1323103#M883</guid>
      <dc:creator>fanheuser_ironport</dc:creator>
      <dc:date>2009-10-28T22:16:06Z</dc:date>
    </item>
  </channel>
</rss>

