cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1589
Views
0
Helpful
0
Replies

FTD/FMC Stream Packet To Splunk (Cisco eStreamer eNcore for Splunk (3.5.1))

SteamCoconut
Beginner
Beginner

I have eStreamer setup to forward logs to our Splunk instance; however, I am not receiving any packet data. 

In the TA-eStreamer setup I have "Packets?" checked.

In the FMC eStreamer Event Configuration, I have "Intrusion Event Packet Data" checked.

 

Since this configuration has been in place we have had an IPS event fire, but no packet was forwarded to Splunk. I ran a search for rec_type_simple=PACKET and did not see any results. Any ideas? Thanks.

0 Replies 0
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers