<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: eStreamer for Splunk error outputting keys and certificates in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430468#M52748</link>
    <description>&lt;P&gt;So I had the same error, "Unable to read password from console. Are you running as a background process?"&lt;BR /&gt;
Here's what I did to troubleshoot:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;CLI into the Splunk server where the TA-eStreamer app is located. &lt;/LI&gt;
&lt;LI&gt;Go to "cd /opt/splunk/etc/apps/TA-eStreamer/bin"
         &lt;STRONG&gt;In the splencore.sh, you may need to edit "#SPLUNK_HOME=/opt/splunk" by removing the #, or set it to Splunk directory.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Run the script: "./splencore.sh test"&lt;/LI&gt;
&lt;LI&gt;It may tell you that the certificate needs the password. Enter the password if prompted. &lt;/LI&gt;
&lt;LI&gt;Once completed, end the script.&lt;/LI&gt;
&lt;LI&gt;Check your eStreamer Summary Dashboard if it's running.&lt;/LI&gt;
&lt;LI&gt;If disabled, go back to the Splunk eStreamer app setup page and try reprocessing the certificate.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;This is how I got mine to work. Good luck!&lt;/P&gt;

&lt;P&gt;Also, you can check out this page for a step by step install: &lt;A href="http://www.thesecurityblogger.com/configuring-cisco-firepower-estreamer-with-splunk-7/"&gt;http://www.thesecurityblogger.com/configuring-cisco-firepower-estreamer-with-splunk-7/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jun 2018 16:49:59 GMT</pubDate>
    <dc:creator>rsanders30</dc:creator>
    <dc:date>2018-06-12T16:49:59Z</dc:date>
    <item>
      <title>eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430467#M52747</link>
      <description>&lt;P&gt;Can anyone help me? I have been trying to resolve this problem for weeks. Although the configuration log changed when I ended up rebuilding both the Splunk and the FMC server.&lt;/P&gt;

&lt;P&gt;The eStreamer encore app always shows disabled. I have checked /opt/splunk/etc/TA=eStreamer/bin/encore and the configuration log shows:&lt;BR /&gt;
Splencore not running&lt;BR /&gt;
Error outputting keys and certificates with the following errors&lt;BR /&gt;
digitial envelope routines:FIPS_CIPHERINIT: disabled for fips:fips_enc.c:142&lt;BR /&gt;
digitial envelope routines:EVP_PBE_CipherInit:keygen failure:evp_pbe.c:197&lt;BR /&gt;
PKCS12 routines:12_pbe_crypt:pkcs12 algor cipherinit error:p12_decr.c:87&lt;BR /&gt;
PKCS12 routines:PKCSS12_item_decrypt_d2i:pkcs12 pbe crypt error:p12_decr.c:138&lt;/P&gt;

&lt;P&gt;The estreamer log has the error: EncoreException: Uable to read password from console. Are you running as a background process?&lt;/P&gt;

&lt;P&gt;I get the same errors whether I use a password or not for the certificate I download from the Firepower Management Center.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:46:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430467#M52747</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2020-09-29T19:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430468#M52748</link>
      <description>&lt;P&gt;So I had the same error, "Unable to read password from console. Are you running as a background process?"&lt;BR /&gt;
Here's what I did to troubleshoot:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;CLI into the Splunk server where the TA-eStreamer app is located. &lt;/LI&gt;
&lt;LI&gt;Go to "cd /opt/splunk/etc/apps/TA-eStreamer/bin"
         &lt;STRONG&gt;In the splencore.sh, you may need to edit "#SPLUNK_HOME=/opt/splunk" by removing the #, or set it to Splunk directory.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Run the script: "./splencore.sh test"&lt;/LI&gt;
&lt;LI&gt;It may tell you that the certificate needs the password. Enter the password if prompted. &lt;/LI&gt;
&lt;LI&gt;Once completed, end the script.&lt;/LI&gt;
&lt;LI&gt;Check your eStreamer Summary Dashboard if it's running.&lt;/LI&gt;
&lt;LI&gt;If disabled, go back to the Splunk eStreamer app setup page and try reprocessing the certificate.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;This is how I got mine to work. Good luck!&lt;/P&gt;

&lt;P&gt;Also, you can check out this page for a step by step install: &lt;A href="http://www.thesecurityblogger.com/configuring-cisco-firepower-estreamer-with-splunk-7/"&gt;http://www.thesecurityblogger.com/configuring-cisco-firepower-estreamer-with-splunk-7/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 16:49:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430468#M52748</guid>
      <dc:creator>rsanders30</dc:creator>
      <dc:date>2018-06-12T16:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430469#M52749</link>
      <description>&lt;P&gt;rsanders30&lt;/P&gt;

&lt;P&gt;Thanks for that update. The change that you posted to edit the splencore.sh file got it so where I could run ./splencore.sh test and start. The problem now is that it fails:&lt;/P&gt;

&lt;P&gt;Traceback (most recent call last):&lt;BR /&gt;
File "./estreamer/preflight.py", line 32 in &lt;BR /&gt;
import argparse&lt;BR /&gt;
ImportError: No module named arparse&lt;/P&gt;

&lt;P&gt;I am no scholar when it comes to Linux and Python, so it leaves me confused.&lt;/P&gt;

&lt;P&gt;If you can provide some direction, I would greatly appreciate it.&lt;/P&gt;

&lt;P&gt;I used the  &lt;A href="http://www.thesecurityblogger.com/configuring-cisco-firepower-estreamer-with-splunk-7/"&gt;http://www.thesecurityblogger.com/configuring-cisco-firepower-estreamer-with-splunk-7/&lt;/A&gt; as my guide to configure this. I also have some other problems too, but I need to take it one by one.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 23:18:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430469#M52749</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2018-06-20T23:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430470#M52750</link>
      <description>&lt;P&gt;Hey moinarf,&lt;/P&gt;

&lt;P&gt;I am no python guru either, but it sounds like you have a python library missing- in this case, argparse, hence it can't run the script. Are you using a Linux or Windows based Splunk? Take a look at the pre-requisites section of the Cisco guide. It contains instructions for installing the python dependencies based on your environment (Windows or Linux). Hope this helps.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/622/api/estreamer_encore/eStreamereNcoreOperationsGuide_30.html#_Toc497831322"&gt;eStreamer eNcore Operations Guide v3.0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 14:20:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430470#M52750</guid>
      <dc:creator>rsanders30</dc:creator>
      <dc:date>2018-06-21T14:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430471#M52751</link>
      <description>&lt;P&gt;rsanders30,&lt;/P&gt;

&lt;P&gt;I am running Splunk in a Linux (RHEL) environment.  I did follow the eStreamer eNcore Operations Guide v3.0. and in the section Pre-requisites, it states that if:&lt;BR /&gt;
1) running the Cisco eSreamer eNcore for Splunk&lt;BR /&gt;
2) provided that the default installation of Splunk which includes Python 2.7 and OpenSSL.&lt;BR /&gt;
then no further action is required. &lt;/P&gt;

&lt;P&gt;Now that I look at it again, I am beginning to wonder a few things that I need to look at. I'll post back after I verify like I am doing the CLI install of this app.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 18:05:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430471#M52751</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2018-06-21T18:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430472#M52752</link>
      <description>&lt;P&gt;Verified the pre-requisites...&lt;/P&gt;

&lt;P&gt;python is located /opt/splunk/bin/python2.7&lt;BR /&gt;
OpenSSL is located in /opt/splunk/bin/openssl&lt;/P&gt;

&lt;P&gt;If Python is install, then I should have the argparse module installed too! &lt;/P&gt;

&lt;P&gt;At this point, I don't know if I should go to Cisco support or Splunk support.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 18:36:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430472#M52752</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2018-06-21T18:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430473#M52753</link>
      <description>&lt;P&gt;Molinarf, were you able to resolve the issue? I am curious to know what the solution was.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 19:59:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430473#M52753</guid>
      <dc:creator>rsanders30</dc:creator>
      <dc:date>2018-06-22T19:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430474#M52754</link>
      <description>&lt;P&gt;No still working on it. I removed the app from Splunk and will re-install. I have another post&lt;BR /&gt;
Splunk eStreamer eNcore client doesn't start at this link &lt;A href="https://answers.splunk.com/answers/667021/splunk-estreamer-encore-client-doesnt-start.html#comment-667366"&gt;https://answers.splunk.com/answers/667021/splunk-estreamer-encore-client-doesnt-start.html#comment-667366&lt;/A&gt;. I am working with a Sam Strathan who wrote some of the python scripts that this app runs. He suggested I try to manually split the keys (public and private) out of the certificate. I am not sure if I'll get to it today, but I will certainly give it a try.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 20:26:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430474#M52754</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2018-06-22T20:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430475#M52755</link>
      <description>&lt;P&gt;molinarf, i read your other post. Have you tried recreating a NEW cert with a password? Once you do that, you can try running the test again unless you continue to get the argparse error. &lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 16:53:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430475#M52755</guid>
      <dc:creator>rsanders30</dc:creator>
      <dc:date>2018-06-25T16:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430476#M52756</link>
      <description>&lt;P&gt;Thanks for following up. I tried to recreate the FMC certificate with and without a password. I even went so far as to change the IP addresses of the FMC, SFRs and their gateways from the management network to a free space on the data network with the same problems. So usually at this point so that I can do my work, I remove eStreamer eNcore and return Splunk to the previous state to clean up and start fresh.&lt;/P&gt;

&lt;P&gt;If you have any other ideas, it would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 17:00:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430476#M52756</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2018-06-25T17:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430477#M52757</link>
      <description>&lt;P&gt;When you tried to recreate the cert, did you try to run another test? I had the same issue, and ran a test after I recreated the cert. It then prompted me to reprocess the cert, and to enter the password. It worked after that. For some reason in the GUI, the re-process doesn't work.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 17:38:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430477#M52757</guid>
      <dc:creator>rsanders30</dc:creator>
      <dc:date>2018-06-25T17:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430478#M52758</link>
      <description>&lt;P&gt;Sure did try that. I tried so many times, I had certs that were named with extensions like 12.pkcs12. Everything gets so messed up when I work on this, I remove the app and the add-on as I said, like a clean start. I use this time to get away from the frustration and catch up on some other work.&lt;/P&gt;

&lt;P&gt;I will probably try again tomorrow or late this afternoon. I just don't know which IP address scheme I should use. To have everything on the data network or to leave it on the management network.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 17:51:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430478#M52758</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2018-06-25T17:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: eStreamer for Splunk error outputting keys and certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430479#M52759</link>
      <description>&lt;P&gt;Finally got back to working on this. I am still having issues with it processing the pcks12 file, but I fixed the argparse file issue.&lt;BR /&gt;
Here is what I did:&lt;BR /&gt;
1) copied a full iso of RHEL6.9 on the Splunk Server&lt;BR /&gt;
2) mounted it into a directory /mnt/iso&lt;BR /&gt;
3) from the Packages directory ran yum install pyton-argpase-&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 23:26:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eStreamer-for-Splunk-error-outputting-keys-and-certificates/m-p/430479#M52759</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2018-10-23T23:26:28Z</dc:date>
    </item>
  </channel>
</rss>

