cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1655
Views
0
Helpful
2
Replies

Latest version of the Sourcefire eStreamer for Splunk

madan_sudhindra
Level 1
Level 1

Hello All,

 

Is there a newer version of the Sourcefire eStreamer for Splunk 6.x ?

We have defense centers running 5.3.x and would like to colleect events into Splunk.

 

Also, is there any way we can have a single instance of the eStreamer client collect data from multiple Defense Centers ?

Thanks and Regards,

Madan Sudhindra

2 Replies 2

dohurd
Cisco Employee
Cisco Employee

Need to know _exactly_ which version of Splunk you're seeing this with.

dohurd
Cisco Employee
Cisco Employee

On the second question, you cannot collect from two DCs with a single client.  You would need to spin up a second instance.

Review Cisco Networking for a $25 gift card