<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sourcefire estreamer in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Sourcefire-estreamer/m-p/57651#M179972</link>
    <description>&lt;P&gt;I'm trying to get estreamer working on splunk.  I have downloaded the splunk app and configured the files in the app according to the README.  The ssl_test.pl script works but when I run the estreamer.py script I get &lt;BR /&gt;
Traceback (most recent call last):&lt;BR /&gt;
  File "./estreamer.py", line 10, in &lt;MODULE&gt;&lt;BR /&gt;
    APP_PATH        = os.path.join(os.environ["SPLUNK_HOME"], 'etc', 'apps', 'Sourcefire')&lt;BR /&gt;
  File "/usr/lib64/python2.6/UserDict.py", line 22, in &lt;STRONG&gt;getitem&lt;/STRONG&gt;&lt;BR /&gt;
    raise KeyError(key)&lt;BR /&gt;
KeyError: 'SPLUNK_HOME'&lt;BR /&gt;
Any help would be appreciated.&lt;/MODULE&gt;&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Tim &lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 14:44:09 GMT</pubDate>
    <dc:creator>timlaw71</dc:creator>
    <dc:date>2020-09-28T14:44:09Z</dc:date>
    <item>
      <title>Sourcefire estreamer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sourcefire-estreamer/m-p/57651#M179972</link>
      <description>&lt;P&gt;I'm trying to get estreamer working on splunk.  I have downloaded the splunk app and configured the files in the app according to the README.  The ssl_test.pl script works but when I run the estreamer.py script I get &lt;BR /&gt;
Traceback (most recent call last):&lt;BR /&gt;
  File "./estreamer.py", line 10, in &lt;MODULE&gt;&lt;BR /&gt;
    APP_PATH        = os.path.join(os.environ["SPLUNK_HOME"], 'etc', 'apps', 'Sourcefire')&lt;BR /&gt;
  File "/usr/lib64/python2.6/UserDict.py", line 22, in &lt;STRONG&gt;getitem&lt;/STRONG&gt;&lt;BR /&gt;
    raise KeyError(key)&lt;BR /&gt;
KeyError: 'SPLUNK_HOME'&lt;BR /&gt;
Any help would be appreciated.&lt;/MODULE&gt;&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Tim &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:44:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sourcefire-estreamer/m-p/57651#M179972</guid>
      <dc:creator>timlaw71</dc:creator>
      <dc:date>2020-09-28T14:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire estreamer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sourcefire-estreamer/m-p/57652#M179973</link>
      <description>&lt;P&gt;You need to export the envrionment variable SPLUNK_HOME in your shell.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;KeyError: 'SPLUNK_HOME'&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2013 15:31:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sourcefire-estreamer/m-p/57652#M179973</guid>
      <dc:creator>edbolton</dc:creator>
      <dc:date>2013-09-24T15:31:39Z</dc:date>
    </item>
  </channel>
</rss>

