All Apps and Add-ons

Can Splunk eStreamer app be used to view Cisco FireSIGHT data from syslog?

Path Finder

I have syslog-ng configured on the same Splunk server to receive syslogs from our Cisco ASA with FireSIGHT. (Will be changing to a seperate syslog server eventually but need to solve this issue before the migration at a later date). The ASA firewall data is being sent to /var/log/cisco_asa and the FireSIGHT data is being sent to /var/log/sourcefire on the Splunk server from the ASA appliance. I have Cisco Security Center, eStreamer for Splunk, Splunk Add-on for Cisco ASA, and Splunk Add-on for Cisco FireSIGHT installed.

I have the /var/log/cisco_asa folder being monitored via Splunk's local inputs under the cisco:asa sourcetype and I am able to see the firewall data with charts on Cisco Security Center app but I am not sure how to see the FireSight IPS data with charts. What sourcetype should I set it up under and what app should I use to see the data? I tried the eStreamer for Splunk app and it seems to only work if data is forwarded from the estreamer port, but not syslog.

0 Karma


Have you checked app? This provides the UI/dashboards/reports. If you are collecting the data via syslog [ has limited data as opposed to using add-on's OR], you may be able to rename/adjust the sourcetype for the 3663 app to analyse the data and report/dashboard it. Just a thought

0 Karma


You are right, the eStreamer app doesn't use syslog. But if you can use eStreamer, why do you feel you need the syslog data from FMC? eStreamer covers all use cases.

From what I remember when we started migrating a few years ago to the firesight stuff, the syslog on it's broken. It just doesn't log all the information one needs in so many cases. The eStreamer app gets the complete data in a timely fashion. So, if I had a suggestion, it is to use eStreamer to collect FMC (e.g. firesight) data, and not worry about syslog for those.

(As it is now, we syslog ASA data and some other similar, we use eStreamer for FireSIGHT and the FMC portions, and we also use the AMP API for all AMP stuff. All three coexist quite nicely.)

0 Karma
Get Updates on the Splunk Community!

Tips & Tricks When Using Ingest Actions

Tune in to learn about:Large scale architecture when using Ingest ActionsRegEx performance considerations ...

Announcing Our Splunk MVPs

We are excited to announce the first cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...