- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have installed Cisco eStreamer app in Splunk and configured to get data from Sourcefire defense center. I am able to see different logs in the eStreamer App dashboard but the Flow logs are "0". I don't see and flow logs.
Could you let me know if there is any additional setting that I need to configure on the Sourcefire or on the Splunk app?
Thanks
Swetha
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Be sure you enable the "Discovery Events" from the System > Local > Registration page on the Defense Center. That is where the flow logs are enabled in eStreamer. Additionally, you will need to enable connection logging in your Access Control policy.
I apologize for not responding earlier -- I've been out of town on business.
Thanks for your interest in eStreamer for Splunk.
Colin Grady
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Colin. This worked! We are able to see the flow logs in Splunk.
Thanks
Swetha
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Be sure you enable the "Discovery Events" from the System > Local > Registration page on the Defense Center. That is where the flow logs are enabled in eStreamer. Additionally, you will need to enable connection logging in your Access Control policy.
I apologize for not responding earlier -- I've been out of town on business.
Thanks for your interest in eStreamer for Splunk.
Colin Grady
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Will this also support Host Discovery events? Thank you.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Colin. This worked. We are able to see flow logs in Splunk.
Thanks
Swetha
