<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Estreamer log collection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/estreamer-log-collection/m-p/4022016#M1010240</link>
    <description>Hi&lt;BR /&gt;&lt;BR /&gt;Did you make sure the connection is working when testing from fmc? All certificates are exchanged between the 2 systems?&lt;BR /&gt;Can you check the status from the expert mode: manage_estreamer.pl status&lt;BR /&gt;&lt;BR /&gt;Here a doc showing how to enable it (start and stop if already enabled):&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firesight/540/api/estreamer/EventStreamerIntegrationGuide/ConfiguringEstreamer.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firesight/540/api/estreamer/EventStreamerIntegrationGuide/ConfiguringEstreamer.html&lt;/A&gt;&lt;BR /&gt;</description>
    <pubDate>Sat, 01 Feb 2020 04:46:13 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2020-02-01T04:46:13Z</dc:date>
    <item>
      <title>Estreamer log collection</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-log-collection/m-p/4021614#M1010239</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We recently upgraded the FMC to 6.2.2 and we re-initiated the logging from the client ( a linux based SIEM) but we observed the below error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error reading events from "FMC IP". java.io.IOException: Connection is broken. Read operation return "-1";&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While running a packet capture on the SIEM, I can see that the FMC is sending a Reset packet but don't know why.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FMC IP.8302 &amp;gt; SIEM IP.25996: Flags [P.], cksum 0x3595 (correct), seq 2137:2228, ack 2761, win 191, length 91&lt;BR /&gt;11:18:49.767299 IP (tos 0x0, ttl 64, id 60754, offset 0, flags [DF], proto TCP (6), length 125)&lt;BR /&gt;SIEM IP.25996 &amp;gt; FMC IP.8302: Flags [P.], cksum 0x6d5a (incorrect -&amp;gt; 0xe280), seq 2761:2846, ack 2228, win 24576, length 85&lt;BR /&gt;11:18:49.767459 IP (tos 0x0, ttl 63, id 63338, offset 0, flags [DF], proto TCP (6), length 109)&lt;BR /&gt;FMC IP.8302 &amp;gt; SIEM IP.25996: Flags [FP.], cksum 0x9e45 (correct), seq 2228:2297, ack 2761, win 191, length 69&lt;BR /&gt;11:18:49.767544 IP (tos 0x0, ttl 63, id 59607, offset 0, flags [DF], proto TCP (6), length 40)&lt;BR /&gt;FMC IP.8302 &amp;gt; SIEM IP.25996: Flags [R], cksum 0xf4a1 (correct), seq 783522214, win 0, length 0&lt;BR /&gt;11:18:49.767555 IP (tos 0x0, ttl 64, id 60755, offset 0, flags [DF], proto TCP (6), length 40)&lt;BR /&gt;SIEM IP.25996 &amp;gt; FMC IP.8302: Flags [.], cksum 0xd827 (correct), ack 2298, win 24576, length 0&lt;BR /&gt;11:18:49.767692 IP (tos 0x0, ttl 64, id 60756, offset 0, flags [DF], proto TCP (6), length 109)&lt;BR /&gt;SIEM IP.25996 &amp;gt; FMC IP.8302: Flags [FP.], cksum 0x6d4a (incorrect -&amp;gt; 0xdb0c), seq 2846:2915, ack 2298, win 24576, length 69&lt;BR /&gt;11:18:49.767767 IP (tos 0x0, ttl 63, id 59608, offset 0, flags [DF], proto TCP (6), length 40)&lt;BR /&gt;FMC IP.8302 &amp;gt; SIEM IP.25996: Flags [R], cksum 0xf45b (correct), seq 783522284, win 0, length 0&lt;BR /&gt;11:18:49.767907 IP (tos 0x0, ttl 63, id 59609, offset 0, flags [DF], proto TCP (6), length 40)&lt;BR /&gt;FMC IP.8302 &amp;gt; SIEM IP.25996: Flags [R], cksum 0xf45b (correct), seq 783522284, win 0, length 0&lt;BR /&gt;11:18:55.781068 IP (tos 0x0, ttl 64, id 50851, offset 0, flags [DF], proto TCP (6), length 52)&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2020 11:35:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-log-collection/m-p/4021614#M1010239</guid>
      <dc:creator>True Warrior</dc:creator>
      <dc:date>2020-01-31T11:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer log collection</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-log-collection/m-p/4022016#M1010240</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Did you make sure the connection is working when testing from fmc? All certificates are exchanged between the 2 systems?&lt;BR /&gt;Can you check the status from the expert mode: manage_estreamer.pl status&lt;BR /&gt;&lt;BR /&gt;Here a doc showing how to enable it (start and stop if already enabled):&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firesight/540/api/estreamer/EventStreamerIntegrationGuide/ConfiguringEstreamer.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firesight/540/api/estreamer/EventStreamerIntegrationGuide/ConfiguringEstreamer.html&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 01 Feb 2020 04:46:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-log-collection/m-p/4022016#M1010240</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-02-01T04:46:13Z</dc:date>
    </item>
  </channel>
</rss>

