<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Firepower eStreamer eNcore 3.6.8 - looping and data delay in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firepower-eStreamer-eNcore-3-6-8-looping-and-data-delay/m-p/490104#M60324</link>
    <description>&lt;P&gt;try to search for some errors on splunkd.log for "eStreamer"&lt;BR /&gt;
Check this procedure for the add-on configuration.&lt;BR /&gt;
&lt;A href="http://www.thesecurityblogger.com/configuring-cisco-firepower-estreamer-with-splunk-7/"&gt;http://www.thesecurityblogger.com/configuring-cisco-firepower-estreamer-with-splunk-7/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Mar 2020 03:07:45 GMT</pubDate>
    <dc:creator>ivanreis</dc:creator>
    <dc:date>2020-03-11T03:07:45Z</dc:date>
    <item>
      <title>Cisco Firepower eStreamer eNcore 3.6.8 - looping and data delay</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firepower-eStreamer-eNcore-3-6-8-looping-and-data-delay/m-p/490103#M60323</link>
      <description>&lt;P&gt;Dear community&lt;/P&gt;

&lt;P&gt;I am trying to onboard the logs from my Cisco FMC (v6.4.0.7) to Splunk (7.3.3), using the app Cisco Firepower eStreamer eNcore (3.6.8) &lt;/P&gt;

&lt;P&gt;the connectivity is OK, I am able to collect some logs during a few minutes.&lt;BR /&gt;
and then the estreamer process stopped/failed.&lt;BR /&gt;
after 15/30 minutes the process is able again to collect some data events from the IDS ... and then fails again&lt;/P&gt;

&lt;P&gt;I don't really know where/what troubleshoot.&lt;BR /&gt;
maybe the default setting  "maxQueueSize": 100.&lt;BR /&gt;
this one can be increased as we have a lot of events.&lt;/P&gt;

&lt;P&gt;thank you so much&lt;/P&gt;

&lt;P&gt;Message output for index=estreamer sourcetype="cisco:estreamer:log"  :&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;Starting process.&lt;BR /&gt;
Starting process.&lt;BR /&gt;
Starting process.&lt;BR /&gt;
Starting Monitor.&lt;BR /&gt;
Using TLS v1.2&lt;BR /&gt;
Connecting to x.x.x.x:8302&lt;BR /&gt;
Connection successful&lt;BR /&gt;
Streaming info response&lt;BR /&gt;
Response message=xxxxx&lt;BR /&gt;
Receiving response message&lt;BR /&gt;
Sending request message&lt;BR /&gt;
Request message=0001000200000008ffffffff48900061&lt;BR /&gt;
Creating request message&lt;BR /&gt;
Using TLS v1.2&lt;BR /&gt;
Connecting to xxxxx:8302&lt;BR /&gt;
Creating connection&lt;BR /&gt;
Check certificate&lt;BR /&gt;
Settings: xxxxxxxx=&lt;BR /&gt;
Processes: 4&lt;BR /&gt;
Sha256: 3xxxxx&lt;BR /&gt;
Platform version: Linux-3.10.0-1062.el7.x86_64-x86_64-with-redhat-7.7-Maipo&lt;BR /&gt;
2020-03-10 11:14:28,556 Controller   INFO     Starting client (pid=25963).&lt;BR /&gt;
eNcore version: 3.6.8&lt;BR /&gt;
Goodbye&lt;BR /&gt;
Stopping Monitor.&lt;BR /&gt;
Process 20330 (Process-4) exit code: 0&lt;BR /&gt;
Exiting&lt;BR /&gt;
Error state. Clearing queue&lt;BR /&gt;
Stop message received&lt;BR /&gt;
Process 20329 (Process-3) exit code: 0&lt;BR /&gt;
Exiting&lt;BR /&gt;
Error state. Clearing queue&lt;BR /&gt;
Stop message received&lt;BR /&gt;
Process 20328 (Process-2) exit code: 0&lt;BR /&gt;
Exiting&lt;BR /&gt;
Error state. Clearing queue&lt;BR /&gt;
Stop message received&lt;BR /&gt;
Process 20327 (Process-1) exit code: 1&lt;BR /&gt;
Stopping...&lt;BR /&gt;
Running. 0 handled; average rate 0 ev/sec;&lt;BR /&gt;
Process subscriberParser is dead.&lt;BR /&gt;
Starting. 0 handled; average rate 0 ev/sec;&lt;BR /&gt;
Starting process.&lt;BR /&gt;
Starting process.&lt;BR /&gt;
Starting process.&lt;BR /&gt;
Starting Monitor.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:32:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firepower-eStreamer-eNcore-3-6-8-looping-and-data-delay/m-p/490103#M60323</guid>
      <dc:creator>vinz2020</dc:creator>
      <dc:date>2020-09-30T04:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower eStreamer eNcore 3.6.8 - looping and data delay</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firepower-eStreamer-eNcore-3-6-8-looping-and-data-delay/m-p/490104#M60324</link>
      <description>&lt;P&gt;try to search for some errors on splunkd.log for "eStreamer"&lt;BR /&gt;
Check this procedure for the add-on configuration.&lt;BR /&gt;
&lt;A href="http://www.thesecurityblogger.com/configuring-cisco-firepower-estreamer-with-splunk-7/"&gt;http://www.thesecurityblogger.com/configuring-cisco-firepower-estreamer-with-splunk-7/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 03:07:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firepower-eStreamer-eNcore-3-6-8-looping-and-data-delay/m-p/490104#M60324</guid>
      <dc:creator>ivanreis</dc:creator>
      <dc:date>2020-03-11T03:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower eStreamer eNcore 3.6.8 - looping and data delay</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firepower-eStreamer-eNcore-3-6-8-looping-and-data-delay/m-p/490105#M60325</link>
      <description>&lt;P&gt;Yes I have this configuration, thank you&lt;/P&gt;

&lt;P&gt;the apps works fine, collecting events on the FMC ... except every 15-20 minutes when the estream app is going down. then it takes a few minutes to restart and collect events again&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 07:40:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firepower-eStreamer-eNcore-3-6-8-looping-and-data-delay/m-p/490105#M60325</guid>
      <dc:creator>vinz2020</dc:creator>
      <dc:date>2020-03-11T07:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower eStreamer eNcore 3.6.8 - looping and data delay</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firepower-eStreamer-eNcore-3-6-8-looping-and-data-delay/m-p/490106#M60326</link>
      <description>&lt;P&gt;can you please check which python version you are running? I am asking because I had an issue on customer where they were running Centos 8 and the python version that was running was python 3.6... I also saw the same exit code at logs.&lt;BR /&gt;
run the script ./splencore.sh test at TA-eStreamer/bin...if you are getting this message:&lt;/P&gt;

&lt;P&gt;./splencore.sh test&lt;BR /&gt;
Traceback (most recent call last):&lt;BR /&gt;
  File "./estreamer/preflight.py", line 33, in &lt;BR /&gt;
    import estreamer.crossprocesslogging&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/&lt;STRONG&gt;init&lt;/STRONG&gt;.py", line 27, in &lt;BR /&gt;
    from estreamer.connection import Connection&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-eStreamer/bin/encore/estreamer/connection.py", line 22, in &lt;BR /&gt;
    import ssl&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/ssl.py", line 98, in &lt;BR /&gt;
    import _ssl             # if we can't import it, let the error propagate&lt;BR /&gt;
ImportError: libssl.so.1.0.0: cannot open shared object file: No such file or directory&lt;/P&gt;

&lt;P&gt;then, do this to fix it:&lt;BR /&gt;
Install Python 2.7&lt;/P&gt;

&lt;P&gt;Edit the python script “splencore.sh” at /opt/splunk/etc/apps/TA-eStreamer/bin and remove # from this line #SPLUNK_HOME=/opt/splunk&lt;/P&gt;

&lt;H1&gt;!/bin/sh&lt;/H1&gt;

&lt;H1&gt;debug&lt;/H1&gt;

&lt;H1&gt;set -x&lt;/H1&gt;

&lt;P&gt;Uncomment #SPLUNK_HOME=/opt/splunk&lt;BR /&gt;
SPLUNK_HOME=/opt/splunk&lt;/P&gt;

&lt;H1&gt;vars&lt;/H1&gt;

&lt;P&gt;pid='-1'&lt;BR /&gt;
configFilepath="estreamer.conf"&lt;BR /&gt;
pybin="python"&lt;BR /&gt;
basepath="$SPLUNK_HOME/etc/apps/TA-eStreamer/bin/encore/"&lt;BR /&gt;
isRunning=0&lt;/P&gt;

&lt;P&gt;save it, restart splunk service.&lt;/P&gt;

&lt;P&gt;The python error was fixed, and after a couple of minutes the data is being receiving properly.&lt;/P&gt;

&lt;P&gt;Also try to play around the Data configuration at addon, on the customer, I select the option "  Connections? This is a very high-volume option and may consume significant network and storage usage"&lt;/P&gt;

&lt;P&gt;These were the steps I took to fix the issue on customer. I hope this can help you.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:33:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firepower-eStreamer-eNcore-3-6-8-looping-and-data-delay/m-p/490106#M60326</guid>
      <dc:creator>ivanreis</dc:creator>
      <dc:date>2020-09-30T04:33:36Z</dc:date>
    </item>
  </channel>
</rss>

