<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Cisco eStreamer for Splunk support eStreamer 6? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202125#M21253</link>
    <description>&lt;P&gt;Arcsight has recently certified their Smart Connector to work with Firepower 5.4.x./  No new schema items supported but it does work with 5.4.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Aug 2016 20:53:42 GMT</pubDate>
    <dc:creator>douglashurd</dc:creator>
    <dc:date>2016-08-15T20:53:42Z</dc:date>
    <item>
      <title>Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202117#M21245</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have not yet found a reference to Splunk eStreamer 6 connectivity in the documentation or the net. Has anyone tested yet if the app allows to pull eStreamer v6? Is there a roadmap date when v6 will be supported?&lt;/P&gt;

&lt;P&gt;Thanks and regards,&lt;BR /&gt;
Oliver&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 17:11:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202117#M21245</guid>
      <dc:creator>Olli1919</dc:creator>
      <dc:date>2016-02-11T17:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202118#M21246</link>
      <description>&lt;P&gt;My organization is successfully using estreamer Version 2.2.1, build 172 with Cisco/Sourcefire 6.0.0 (build 1005).   As documented in the release notes, pulling connection events can be hours behind.  We had the same delays with Cisco/Sourcefire 5.x.   All other estreamer events are pulled in a timely fashion.    I do not know if there is a roadmap for official v6 support.   You can trying contacting the author of the app.  &lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 18:14:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202118#M21246</guid>
      <dc:creator>sjaworski</dc:creator>
      <dc:date>2016-02-11T18:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202119#M21247</link>
      <description>&lt;P&gt;There is a plan to build a new app.  Its at a very early stage right now.  Some number of months but it is planned.&lt;/P&gt;

&lt;P&gt;The current app will work with FireSIGHT 6 but the data set will be the same as with 5.4.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 19:01:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202119#M21247</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2016-02-11T19:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202120#M21248</link>
      <description>&lt;P&gt;Thank you for your replies. It is good to see Cisco extends the functionality. Looking at the Integration side, ArcSight seems to have said that they do not support eStreamer in the future, as they want CEF. I am not surprised to see this development. I just hope that open interfaces remain as important for the players as they are for their customers.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2016 09:27:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202120#M21248</guid>
      <dc:creator>Olli1919</dc:creator>
      <dc:date>2016-02-12T09:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202121#M21249</link>
      <description>&lt;P&gt;To clarify.  We built an eStreamer client that converts the binary output from the API's Server to text and into a CEF format.  Arcsight is no longer building on their eStreamer client known as a 'Smart Connector'.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2016 16:02:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202121#M21249</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2016-03-22T16:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202122#M21250</link>
      <description>&lt;P&gt;Does anyone know who we need to pressure to increase the priority of the new version.   I lost detail of meaningful user ID's on the data stream from 5.X to 6.X SourceFire because cisco(SourceFire) changed the way the internal database deals with user ID's to allow for multiple user realms.  all I see now in the stream is the numeric representation of what I assume is a unique identifier for the user in a one t many database. &lt;BR /&gt;
I have taken it to my enterprise rep but have heard nothing.   I also have a ticket in on the issue.  &lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2016 16:48:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202122#M21250</guid>
      <dc:creator>JimGatMBCI</dc:creator>
      <dc:date>2016-05-09T16:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202123#M21251</link>
      <description>&lt;P&gt;Are you seeing user ID's&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2016 16:49:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202123#M21251</guid>
      <dc:creator>JimGatMBCI</dc:creator>
      <dc:date>2016-05-09T16:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202124#M21252</link>
      <description>&lt;P&gt;We have many customers running Firepower 6.0 with Splunk and the current Cisco eStreamer for Splunk App.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2016 20:52:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202124#M21252</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2016-08-15T20:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202125#M21253</link>
      <description>&lt;P&gt;Arcsight has recently certified their Smart Connector to work with Firepower 5.4.x./  No new schema items supported but it does work with 5.4.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2016 20:53:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202125#M21253</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2016-08-15T20:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202126#M21254</link>
      <description>&lt;P&gt;I think the issue is the current app doesn't pull in all of the new fields that v6 has to offer.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2016 21:43:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202126#M21254</guid>
      <dc:creator>rsolutions</dc:creator>
      <dc:date>2016-08-15T21:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202127#M21255</link>
      <description>&lt;P&gt;That is correct.  The app was built against the 5.4 API specification.  New stuff in 6.0 won't be forwarded.&lt;/P&gt;

&lt;P&gt;What fields are you looking for?  Do you know?&lt;/P&gt;

&lt;P&gt;Doug&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 14:35:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202127#M21255</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2016-08-16T14:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202128#M21256</link>
      <description>&lt;P&gt;I am working on a Splunk implementation for a large Telco... I'll ask, but I'm pretty sure the comment will be all fields as they have an extensive Splunk deployment.  &lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 14:37:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202128#M21256</guid>
      <dc:creator>rsolutions</dc:creator>
      <dc:date>2016-08-16T14:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202129#M21257</link>
      <description>&lt;P&gt;OK good to know.  If you can share any specifics or the country it would help me build the case for a new eStreamer app.  I can be emailed directly here:  &lt;A href="mailto:dohurd@cisco.com"&gt;dohurd@cisco.com&lt;/A&gt;  I track this stuff.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 14:44:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202129#M21257</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2016-08-16T14:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202130#M21258</link>
      <description>&lt;P&gt;I am looking for all fields as we use Splunk for our long term storage since the Defense Center (FireSight..) can only hold about a day of our data at best.   &lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 15:08:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202130#M21258</guid>
      <dc:creator>JimGatMBCI</dc:creator>
      <dc:date>2016-08-16T15:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202131#M21259</link>
      <description>&lt;P&gt;We opened a ticket with Cisco and were pointed towards this bug entry: &lt;A href="https://tools.cisco.com/bugsearch/bug/CSCuz95008/?reffering_site=dumpcr"&gt;CSCuz95008&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;It appears to be that the &lt;A href="https://splunkbase.splunk.com/app/1629/"&gt;Cisco eStreamer for Splunk App&lt;/A&gt; (currently v2.2.2) does not support the eStreamer user metadata format which was changed in 6.0.  We are currently using Cisco FMC 6.1.0.1, Splunk 6.5.2 and eStreamer 2.2.2.  As a result, our connection events reference a numerical value for the 'user' field instead of the actual username.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 18:51:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202131#M21259</guid>
      <dc:creator>jmartincot</dc:creator>
      <dc:date>2017-02-21T18:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202132#M21260</link>
      <description>&lt;P&gt;In case anyone else is looking for this, I can happily confirm that upgrading FMC and Firepower appliances to 6.2.0 resolves the issue with user IDs (CSCuz95008). We now have correct user IDs populated in the events.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2017 07:20:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202132#M21260</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2017-03-17T07:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202133#M21261</link>
      <description>&lt;P&gt;I was able to upgrade our Firepower Appliance to 6.1.0.3 and the issue was resolved.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2017 15:10:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202133#M21261</guid>
      <dc:creator>jmartincot</dc:creator>
      <dc:date>2017-03-17T15:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202134#M21262</link>
      <description>&lt;P&gt;A new Cisco eStreamer fro Splunk client/TA will be available in the end of April  The current app does work with 6.x but there have been some reported issues.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 11:50:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202134#M21262</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2017-03-27T11:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202135#M21263</link>
      <description>&lt;P&gt;@douglashurd&lt;BR /&gt;
Looking for an update to both the eStreamer app and accompanying "Splunk Add-on for Cisco FireSIGHT" that's compatible with FMC 6.2.x.  Since the field names have changed, the TA is no longer fully CIM compliant with the Intrusion Detection data model...which means info also is missing from Enterprise Security dashboards.   This is just one of many possible examples.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 22:10:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202135#M21263</guid>
      <dc:creator>ChrisBell04</dc:creator>
      <dc:date>2017-07-20T22:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco eStreamer for Splunk support eStreamer 6?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202136#M21264</link>
      <description>&lt;P&gt;There is a new add on for Firepower 6.x customers available right now:  &lt;A href="https://splunkbase.splunk.com/app/3662/"&gt;https://splunkbase.splunk.com/app/3662/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 16:54:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Cisco-eStreamer-for-Splunk-support-eStreamer-6/m-p/202136#M21264</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2017-08-02T16:54:01Z</dc:date>
    </item>
  </channel>
</rss>

