Hi just installed the app , did the setup .
When checked splencore.sh status it seems to be running (had to remove the remark before the SPLUNK_HOME to make it run).
Also temp files under /opt/splunk/etc/apps/TA-estreamer/data
is building .
All scripts and data file readers are enabled but somehow when I search for index=* sourcetype=cisco:estreamer:data
nothing shows up (time range is set to All time).
Tried to remove the app restarted Splunk and reinstalled add-on nothing changed.
Anyone had the same problem?
what version of Firepower? eNcore? When you say app, you mean the TA?