<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Utilize on-prem Splunk Heavy Forwarder with Cisco Security Cloud for FMC logs into Splunk Cloud instance in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/748140#M118889</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;I tried the query that you suggested to check internal logs for my HF and tweaked key words to see anything related to FMC/Cisco/estreamer. But, it does not show any error logs.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jun 2025 16:40:46 GMT</pubDate>
    <dc:creator>parthbhawsar</dc:creator>
    <dc:date>2025-06-17T16:40:46Z</dc:date>
    <item>
      <title>Utilize on-prem Splunk Heavy Forwarder with Cisco Security Cloud for FMC logs into Splunk Cloud instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/747947#M118837</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have been trying to configure this application on one of our on-prem Heavy forwarder to be able to ingest our FMC logs to our Splunk Cloud instance. I have so far been able to install the latest version of the app on Heavy Forwarder and configure the FMC section via estreamer configuration and was able to save it. I have also created the index both on HF and Splunk Cloud instance. However, I don't seem to be getting the logs into the cloud instance through that source. I am trying to find out what additional steps are needed to be able to make it work. Hopefully, if someone has had similar issue and were able to fix it or know how to resolve it then please let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#ciscosecuritycloud&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 15:09:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/747947#M118837</guid>
      <dc:creator>parthbhawsar</dc:creator>
      <dc:date>2025-06-13T15:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: Utilize on-prem Splunk Heavy Forwarder with Cisco Security Cloud for FMC logs into Splunk Cloud instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/747955#M118839</link>
      <description>&lt;P&gt;1. Be a bit more precise on how you defined the HF&lt;/P&gt;&lt;P&gt;2. You don't need an index on the HF.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 20:42:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/747955#M118839</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-06-13T20:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Utilize on-prem Splunk Heavy Forwarder with Cisco Security Cloud for FMC logs into Splunk Cloud instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/747958#M118840</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310928"&gt;@parthbhawsar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you been able to confirm that HF is sending all its events to Splunk Cloud? ie Have you installed the UF app from your Splunk Cloud instance and been able to see the HF's _internal logs in Splunk Cloud?&lt;/P&gt;&lt;P&gt;If so are you able to see any error logs in _internal in relation to the Cisco app? For example:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal "error" ("cisco" OR "fmc")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Sat, 14 Jun 2025 10:20:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/747958#M118840</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-14T10:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Utilize on-prem Splunk Heavy Forwarder with Cisco Security Cloud for FMC logs into Splunk Cloud instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/747981#M118849</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310928"&gt;@parthbhawsar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have recently configured the Cisco FMC and successfully integrated it with Splunk. Could you please check the error you are encountering in Splunk so that I can assist you further? If you continue to face any issues, I would recommend reaching out to the Cisco TAC team for additional support.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 02:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/747981#M118849</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-06-16T02:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Utilize on-prem Splunk Heavy Forwarder with Cisco Security Cloud for FMC logs into Splunk Cloud instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/748139#M118888</link>
      <description>&lt;P&gt;I have configured the Cisco Security Cloud app on the HF because our FMC is not allowed to have any outbound access. As far as the configuration is concerned, I was able to import the cert from FMC and save the configuration in the Cisco Security Cloud app. I also created the index on HF as well as cloud instance. But, I don't see any logs from that source into the cloud. I checked the internal logs for the HF and I don't see any errors related to this.&lt;/P&gt;&lt;P&gt;I am adding the screenshot from the app configuration on the HF. It does not show the status as&amp;nbsp; "Connected"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="parthbhawsar_3-1750178041808.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39394i935617B98B6D59F6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="parthbhawsar_3-1750178041808.png" alt="parthbhawsar_3-1750178041808.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried opening a Cisco TAC Case, but as soon as I select the product category to Splunk, it asks me to open a ticket with Splunk support. So, I have been trying to figure out how to contact Cisco Support for the app add-on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI additional info, I also have the Cisco Security Cloud app on the cloud instance, which I am using for integration with another Cisco cloud product which seems to be working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 16:38:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/748139#M118888</guid>
      <dc:creator>parthbhawsar</dc:creator>
      <dc:date>2025-06-17T16:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Utilize on-prem Splunk Heavy Forwarder with Cisco Security Cloud for FMC logs into Splunk Cloud instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/748140#M118889</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;I tried the query that you suggested to check internal logs for my HF and tweaked key words to see anything related to FMC/Cisco/estreamer. But, it does not show any error logs.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 16:40:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Utilize-on-prem-Splunk-Heavy-Forwarder-with-Cisco-Security-Cloud/m-p/748140#M118889</guid>
      <dc:creator>parthbhawsar</dc:creator>
      <dc:date>2025-06-17T16:40:46Z</dc:date>
    </item>
  </channel>
</rss>

