<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: eStreamer config question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/estreamer-config-question/m-p/4040974#M1067400</link>
    <description>&lt;P&gt;I did, and I got as far as having eStreamer write a local .json file. I'd like to be able to pipe the output directly to logstash, though, without having to write a file in the middle. I'm using the Python-based eStreamer client we downloaded from Cisco, and the manual you refer to is showing config for the Perl one. I'm just not clear on how to set up the outputters: section to push the data directly over udp to the logstash listener.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Mar 2020 15:12:29 GMT</pubDate>
    <dc:creator>sdkeslar2012</dc:creator>
    <dc:date>2020-03-05T15:12:29Z</dc:date>
    <item>
      <title>eStreamer config question</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-config-question/m-p/4040163#M1067316</link>
      <description>&lt;P&gt;Trying to get data out of our FMC to our SIEM. How do&amp;nbsp; you set up estreamer.conf to send the data to a tcp port? The operations guide mentions it, but not how to do it.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 13:41:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-config-question/m-p/4040163#M1067316</guid>
      <dc:creator>sdkeslar2012</dc:creator>
      <dc:date>2020-03-04T13:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer config question</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-config-question/m-p/4040576#M1067361</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;Did you check this config guide:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firesight/540/api/estreamer/EventStreamerIntegrationGuide/ConfiguringEstreamer.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firesight/540/api/estreamer/EventStreamerIntegrationGuide/ConfiguringEstreamer.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;It explains all the configuration&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 03:12:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-config-question/m-p/4040576#M1067361</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-03-05T03:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer config question</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-config-question/m-p/4040974#M1067400</link>
      <description>&lt;P&gt;I did, and I got as far as having eStreamer write a local .json file. I'd like to be able to pipe the output directly to logstash, though, without having to write a file in the middle. I'm using the Python-based eStreamer client we downloaded from Cisco, and the manual you refer to is showing config for the Perl one. I'm just not clear on how to set up the outputters: section to push the data directly over udp to the logstash listener.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 15:12:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-config-question/m-p/4040974#M1067400</guid>
      <dc:creator>sdkeslar2012</dc:creator>
      <dc:date>2020-03-05T15:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer config question</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-config-question/m-p/4041204#M1067415</link>
      <description>Ok you're looking for the config on logstash side?&lt;BR /&gt;I didn't do it with logstash yet. I can take a look ove the weekend</description>
      <pubDate>Thu, 05 Mar 2020 19:45:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-config-question/m-p/4041204#M1067415</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-03-05T19:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer config question</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-config-question/m-p/4041257#M1067423</link>
      <description>&lt;P&gt;No, the LS config seems fine. I'd like to eliminate writing the eStreamer data to disk. Having an issue where it pushes about 1.5GB of data, then just stops writing to the file. Status still shows it thinks it's processing events. I actually got it to try to send over UDP to LS, but then eStreamer was complaining that the data was too large.. arggh.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 20:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-config-question/m-p/4041257#M1067423</guid>
      <dc:creator>sdkeslar2012</dc:creator>
      <dc:date>2020-03-05T20:52:12Z</dc:date>
    </item>
  </channel>
</rss>

