12-16-2024 02:08 AM
Hello,
We are experiencing an issue with the Cisco Firepower eStreamer integration to Microsoft Sentinel. We successfully integrated the eStreamer and started receiving logs from Cisco Firepower to Microsoft Sentinel. However, after 2 or 3 days, the logs stopped being ingested into Microsoft Sentinel.
When we restarted the eStreamer, the logs resumed flowing into Microsoft Sentinel, but the issue repeats after a few days.
We have been using the Cisco Firepower eStreamer enCore Sentinel Operations Guide and the CiscoSecurity fp-05-microsoft-sentinel-connector GitHub repository for the integration.
However, we are encountering the following error in the logs, which seems to be causing a failure in the log ingestion process:
2024-12-12 09:49:37,014 Subscriber INFO Stop message received
2024-12-12 09:49:37,015 Monitor ERROR Monitor __start: 'TypeError' object has no attribute 'message'
2024-12-12 09:51:37,617 Subscriber INFO Exiting
2024-12-12 09:51:37,617 Controller INFO Process 2000662 (Process-1) exit code: 0
2024-12-12 09:51:37,617 Parser INFO Stop message received
How can we resolve the TypeError: 'TypeError' object has no attribute 'message' error and prevent the logs from stopping after a few days in the eStreamer integration with Microsoft Sentinel?
12-16-2024 02:19 AM
It seem that MS is behind NAT ?
MHM
12-19-2024 01:24 AM
Thank you for your response.
Microsoft Sentinel is not behind NAT in our setup. The eStreamer integration works fine initially, and logs are ingested successfully. However, the issue arises after 2–3 days when the logs stop being ingested, and we have to restart the eStreamer service to restore the flow.
Could there be another configuration or compatibility issue causing this behavior? We’d appreciate any guidance on resolving the error 'TypeError' object has no attribute 'message' and ensuring consistent log ingestion.
Thank you!
12-19-2024 02:19 AM
https://bst.cisco.com/bugsearch/bug/CSCvp34384?rfs=qvlogin <<- this log message can be bug open TAC as workaround suggest
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide