cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1818
Views
0
Helpful
0
Replies

Cisco Firepower eStreamer eNcore Add-on for Splunk 3.6.8 not CIM compatible?

Jonathan Hall
Level 1
Level 1

Is anyone using TA-eStreamer 3.6.8 with Splunk Enterprise Security?

 

Although the add-on says it's CIM 4.x compatible we're not seeing any of the cisco:estreamer:data sourcetype matching data models.

 

Looking at the add-on it doesn't have any tags.conf or eventtypes.conf files so nothing to tie it to the appropriate CIM data models.

0 Replies 0
Review Cisco Networking for a $25 gift card