cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1031
Views
2
Helpful
18
Replies

Cisco eStreamer with FMC & Microsoft sentinel

AshbyJohnDNV
Level 1
Level 1

Hi, have a successful connection of FMC with eStreamer and can see syslog in Sentinel. However see this error against the DCR rule int Sentinel. Even though the DCR rule is created does this mean no events in CEF format reaching Sentinel? 

AshbyJohnDNV_0-1733318849975.png

FMC is on version 7.4.1.1

Redhat Linux 9 Ent

Python 3

  

18 Replies 18

Chekol Retta
Level 1
Level 1

I wonder if someone can provide installation files and technical guides. 

For the Estreamer?

For eNcore and sentinel

Once the log reaches to Azure/syslog forwarders.