cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Questions re TA-eStreamer & multiple FMC

ww9rivers
Beginner
Beginner

Got two questions:

  1. The latest Operations Guide states that "eNcore can only currently support one server". And this post on Splunk>answer says that they had to "contact Cisco directly and get the CLI version of estreamer". Are these info still correct with regard to the latest TA-eStreamer version 3.6.8?
  2. Looking into the TA-eStreamer 3.6.8 code a bit, I see that it mandates Python 2.7. With that going away, what is Cisco's plan for Python 3 support?

Thank you much!

@nspasov 

2 REPLIES 2

ww9rivers
Beginner
Beginner
Attempting to answer my 1st question: The default TA-eStreamer input is basically a Splunk scripted input, calling the bin/splencore.sh script to talk to an FMC. That script has a hard-coded "configFilepath".
SO -- as a quick hack, if I make a copy of the "bin/splencore.sh" and modify the "configFilepath", I should be able to create a second scripted input in inputs.conf. Would that be correct?
I'm going to give it a try and report back later.

Happy to report that my very quick and simple hack actually works.
If any one is interested, I may be able to clone the app and put it on Github if Cisco is OK with that.
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: