All Apps and Add-ons

Can you input Cisco ASA Firepower IPS alerts into Splunk?

Keef2112
New Member

Hi, can you input Cisco ASA Firepower IPS alerts and events into Splunk? Then present these events as a dashboard?

0 Karma

Dijanad
New Member

As far as the estreamer app...the instructions say data import doesn't work in windows, is that correct?

Is there a way to do it by connecting the IPS eStreamer to splunk and get the events that way, without using apps?

0 Karma

Richfez
SplunkTrust
SplunkTrust

Yes you can!

Take a look at the two apps for Cisco eNcore (I hate that capitalization). The eStreamer one is what you use to collect the data from the FMC, and the other one should give you pretty dashboards of that data.

Follow the instructions carefully for the eStreamer app to start collecting that data, but if you have any problems ask us about them!

Happy Splunking,
Rich

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...

Index This | How many sevens are there between 1 and 100?

August 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...