<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Estreamer to Logstash? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389340#M923820</link>
    <description>&lt;P&gt;There is a sort of generic estreamer client called eNcore which supports plug ins.&amp;nbsp; The base client code simple collects all the events from the estreamer queue on the FMC and converts this binary data to text and writes it to disk.&amp;nbsp; There is a Splunk, CEF and JSON plugins and a few 3rd parties have written their own.&amp;nbsp; &amp;nbsp; Maybe a logstash plugin could be written.&amp;nbsp; Please email me at dohurd@cisco.com if you want to know more&lt;/P&gt;</description>
    <pubDate>Fri, 25 May 2018 15:47:53 GMT</pubDate>
    <dc:creator>dohurd</dc:creator>
    <dc:date>2018-05-25T15:47:53Z</dc:date>
    <item>
      <title>Estreamer to Logstash?</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3388928#M923817</link>
      <description>&lt;P&gt;Does anyone have a sample config they have used to retrieve event streamer data to logstash? Seems to be the only way to get relevant alerting beings there is no api access to retrieve signature alerts or anything like that.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:48:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3388928#M923817</guid>
      <dc:creator>babiojd01</dc:creator>
      <dc:date>2020-02-21T15:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer to Logstash?</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389172#M923818</link>
      <description>&lt;P&gt;Do you need it also for IDS events? Cause I have the problem that the new FTD IDS sensor seems not to send any IDS events, only ACP Events...&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 11:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389172#M923818</guid>
      <dc:creator>SeSc</dc:creator>
      <dc:date>2018-05-25T11:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer to Logstash?</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389198#M923819</link>
      <description>&lt;P&gt;Our environment is purely Firepower on top of ASA. Currently no production FTD so hopefully whatever you have works?&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 12:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389198#M923819</guid>
      <dc:creator>babiojd01</dc:creator>
      <dc:date>2018-05-25T12:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer to Logstash?</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389340#M923820</link>
      <description>&lt;P&gt;There is a sort of generic estreamer client called eNcore which supports plug ins.&amp;nbsp; The base client code simple collects all the events from the estreamer queue on the FMC and converts this binary data to text and writes it to disk.&amp;nbsp; There is a Splunk, CEF and JSON plugins and a few 3rd parties have written their own.&amp;nbsp; &amp;nbsp; Maybe a logstash plugin could be written.&amp;nbsp; Please email me at dohurd@cisco.com if you want to know more&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 15:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389340#M923820</guid>
      <dc:creator>dohurd</dc:creator>
      <dc:date>2018-05-25T15:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer to Logstash?</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389341#M923821</link>
      <description>&lt;P&gt;There is a sort of generic estreamer client called eNcore which supports plug ins.&amp;nbsp; The base client code simple collects all the events from the estreamer queue on the FMC and converts this binary data to text and writes it to disk.&amp;nbsp; There is a Splunk, CEF and JSON plugins and a few 3rd parties have written their own.&amp;nbsp; &amp;nbsp; Maybe a logstash plugin could be written.&amp;nbsp; Please email me at dohurd@cisco.com if you want to know more&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 15:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389341#M923821</guid>
      <dc:creator>dohurd</dc:creator>
      <dc:date>2018-05-25T15:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer to Logstash?</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389705#M923822</link>
      <description>&lt;P&gt;&lt;A href="https://developer.cisco.com/site/firepower/" target="_blank"&gt;https://developer.cisco.com/site/firepower/&lt;/A&gt; so I downloaded this to pull the events via estreamer. The csv file part doesn't seem to work. The only thing that does work is sending the alerts to syslog or send them to print screen. If I could get the events via json I know how to parse them into logstash.&lt;/P&gt;</description>
      <pubDate>Sat, 26 May 2018 23:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389705#M923822</guid>
      <dc:creator>babiojd01</dc:creator>
      <dc:date>2018-05-26T23:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer to Logstash?</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389837#M923823</link>
      <description>I have figured out how to use the sdk to get the estreamer output to syslog but I don't see alerts for malware events. I do see them when the output is switched print. Anyone have any insight?</description>
      <pubDate>Sun, 27 May 2018 18:03:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3389837#M923823</guid>
      <dc:creator>babiojd01</dc:creator>
      <dc:date>2018-05-27T18:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer to Logstash?</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3408140#M923824</link>
      <description>&lt;P&gt;If help is still needed on eStreamer and Logstash please email me directly at dohurd@cisco.com.&amp;nbsp; IDS event data as well as AMP and Connection events ARE available directly off the FTD device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 17:48:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3408140#M923824</guid>
      <dc:creator>dohurd</dc:creator>
      <dc:date>2018-06-29T17:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer to Logstash?</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3414132#M923825</link>
      <description>&lt;P&gt;I thankfully received the encore client from Doug at cisco but for some reason or another i only receive some alerts not every thing coming from the FirePower Manager. I ran specific tests and I see my snort alerts go out via syslog to the syslog server but estreamer isn't send them? Very strange behavior.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 16:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3414132#M923825</guid>
      <dc:creator>babiojd01</dc:creator>
      <dc:date>2018-07-11T16:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer to Logstash?</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3417181#M923826</link>
      <description>&lt;P&gt;You might need to build a plug in for LogStash if you want to use eStreamer.&amp;nbsp; To really figure it out we'd need to speak on the phone probably.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 21:35:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3417181#M923826</guid>
      <dc:creator>dohurd</dc:creator>
      <dc:date>2018-07-17T21:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer to Logstash?</title>
      <link>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3417448#M923827</link>
      <description>&lt;P&gt;Its fine, I am currently pulling the alerts in via RSA netwitness using their API. It just would've been nice if this was as simple as pulling the CTA logs via the api or if pulling snort alerts from FMC was available via the api. Is that functionality coming any time soon? This type of alerting integration would simplified if so.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 11:20:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/estreamer-to-logstash/m-p/3417448#M923827</guid>
      <dc:creator>babiojd01</dc:creator>
      <dc:date>2018-07-18T11:20:53Z</dc:date>
    </item>
  </channel>
</rss>

