All Apps and Add-ons

Can Splunk eStreamer app be used to view Cisco FireSIGHT data from syslog?

Path Finder

I have syslog-ng configured on the same Splunk server to receive syslogs from our Cisco ASA with FireSIGHT. (Will be changing to a seperate syslog server eventually but need to solve this issue before the migration at a later date). The ASA firewall data is being sent to /var/log/cisco_asa and the FireSIGHT data is being sent to /var/log/sourcefire on the Splunk server from the ASA appliance. I have Cisco Security Center, eStreamer for Splunk, Splunk Add-on for Cisco ASA, and Splunk Add-on for Cisco FireSIGHT installed.

I have the /var/log/cisco_asa folder being monitored via Splunk's local inputs under the cisco:asa sourcetype and I am able to see the firewall data with charts on Cisco Security Center app but I am not sure how to see the FireSight IPS data with charts. What sourcetype should I set it up under and what app should I use to see the data? I tried the eStreamer for Splunk app and it seems to only work if data is forwarded from the estreamer port, but not syslog.

0 Karma


Have you checked app? This provides the UI/dashboards/reports. If you are collecting the data via syslog [ has limited data as opposed to using add-on's OR], you may be able to rename/adjust the sourcetype for the 3663 app to analyse the data and report/dashboard it. Just a thought

0 Karma


You are right, the eStreamer app doesn't use syslog. But if you can use eStreamer, why do you feel you need the syslog data from FMC? eStreamer covers all use cases.

From what I remember when we started migrating a few years ago to the firesight stuff, the syslog on it's broken. It just doesn't log all the information one needs in so many cases. The eStreamer app gets the complete data in a timely fashion. So, if I had a suggestion, it is to use eStreamer to collect FMC (e.g. firesight) data, and not worry about syslog for those.

(As it is now, we syslog ASA data and some other similar, we use eStreamer for FireSIGHT and the FMC portions, and we also use the AMP API for all AMP stuff. All three coexist quite nicely.)

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...