02-03-2015 03:07 PM - edited 03-12-2019 05:37 AM
Hello All,
Is there a newer version of the Sourcefire eStreamer for Splunk 6.x ?
We have defense centers running 5.3.x and would like to colleect events into Splunk.
Also, is there any way we can have a single instance of the eStreamer client collect data from multiple Defense Centers ?
Thanks and Regards,
Madan Sudhindra
02-04-2015 07:19 AM
Need to know _exactly_ which version of Splunk you're seeing this with.
02-04-2015 07:23 AM
On the second question, you cannot collect from two DCs with a single client. You would need to spin up a second instance.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide