cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
618
Views
0
Helpful
1
Replies

How to set it up eNcore outputters to connect with the Elasticsearch

jonggkim
Level 1
Level 1

I want to send the log directly from eNcore to elasticsearch.

Please teach me the way.
1 Reply 1

adrian_iovita
Level 1
Level 1

You can use the client from github https://github.com/CiscoSecurity/fp-05-firepower-cli/tree/master

once you install the client you can create an outputter in json or CEF format that will point to your filebeat. filebeat is able to parse json or CEF format. and Then forward those logs to logstash

Review Cisco Networking for a $25 gift card