cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
835
Views
2
Helpful
2
Replies

eStreamer / EncoreCLI

pactag23
Level 1
Level 1

Now that eStreamer is at EOL, what are our options to stream events from a Firepower into Microsoft Sentinel?

We are not a Splunk customer, and the page linked here says something about building your own application which isn't something that I have the skills to do. What is everyone else using now?

Python 2.7 is EOL and the current eStreamer package does not work with Python 3.10, which is the latest available on Ubuntu. I have the same issue as here.

2 Replies 2

zrahim
Level 1
Level 1

@marce1000 any comment?

pactag23
Level 1
Level 1

Just an update for anyone reading, what I ended up doing was building a new Azure VM with Ubuntu 20.04.6 LTS. That version of Ubuntu has support for Python 2.7, and I was then able to get eStreamer working again.

The OS is end of support this year, but for a small monthly fee I was able to purchase Ubuntu Pro that gives us another 5 years of support.

Review Cisco Networking for a $25 gift card