<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CiscoSecurityCloud TA 3.6.7 -eStreamer ingestion falling behind by several hours under high log volume from a single FMC in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/CiscoSecurityCloud-TA-3-6-7-eStreamer-ingestion-falling-behind/m-p/761829#M120601</link>
    <description>&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;We are using the CiscoSecurityCloud TA 3.6.7 to ingest firewall events via eStreamer from a single FMC that has 5 firewall groups connected to it. We cannot separate these groups across multiple FMC instances as they are all managed by one FMC. Event types we collect are ConnectionEvent, IntrusionEvent, and FileEvent, with import_time_range set to from_now.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;The ingestion is consistently falling behind real-time, and the delay grows with log volume. During peak traffic hours the lag reaches several hours.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;We already verified the eStreamer TCP connection to FMC is stable with no disconnects or SSL errors, and the delay is directly correlated with traffic volume — low traffic gives around 40 minutes delay while high traffic pushes it to several hours.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;Our questions are: Is this a known limitation when a single FMC manages multiple high-traffic firewall groups over one eStreamer connection? Are there any tuning options in CiscoSecurityCloud TA 3.6.7 to improve throughput such as chunk size or socket buffer settings? And is there any recommended workaround for this scenario where splitting the FMC is not an option?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;Any guidance from the community or Cisco/Splunk engineers would be greatly appreciated.&lt;BR /&gt;&lt;LI-PRODUCT title="Cisco Security Cloud" id="7404"&gt;&lt;/LI-PRODUCT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 22 Jun 2026 17:58:51 GMT</pubDate>
    <dc:creator>refahiati</dc:creator>
    <dc:date>2026-06-22T17:58:51Z</dc:date>
    <item>
      <title>CiscoSecurityCloud TA 3.6.7 -eStreamer ingestion falling behind by several hours under high log volume from a single FMC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CiscoSecurityCloud-TA-3-6-7-eStreamer-ingestion-falling-behind/m-p/761829#M120601</link>
      <description>&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;We are using the CiscoSecurityCloud TA 3.6.7 to ingest firewall events via eStreamer from a single FMC that has 5 firewall groups connected to it. We cannot separate these groups across multiple FMC instances as they are all managed by one FMC. Event types we collect are ConnectionEvent, IntrusionEvent, and FileEvent, with import_time_range set to from_now.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;The ingestion is consistently falling behind real-time, and the delay grows with log volume. During peak traffic hours the lag reaches several hours.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;We already verified the eStreamer TCP connection to FMC is stable with no disconnects or SSL errors, and the delay is directly correlated with traffic volume — low traffic gives around 40 minutes delay while high traffic pushes it to several hours.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;Our questions are: Is this a known limitation when a single FMC manages multiple high-traffic firewall groups over one eStreamer connection? Are there any tuning options in CiscoSecurityCloud TA 3.6.7 to improve throughput such as chunk size or socket buffer settings? And is there any recommended workaround for this scenario where splitting the FMC is not an option?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;Any guidance from the community or Cisco/Splunk engineers would be greatly appreciated.&lt;BR /&gt;&lt;LI-PRODUCT title="Cisco Security Cloud" id="7404"&gt;&lt;/LI-PRODUCT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 22 Jun 2026 17:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CiscoSecurityCloud-TA-3-6-7-eStreamer-ingestion-falling-behind/m-p/761829#M120601</guid>
      <dc:creator>refahiati</dc:creator>
      <dc:date>2026-06-22T17:58:51Z</dc:date>
    </item>
  </channel>
</rss>

