Does anyone know if the eStreamer catches up with the data from the Sourcefire Defense Center after the eStreamer has been shut down for say, one hour? Or would this eventually lead to an hour of "missed events" in Splunk?
Thanks in Advance, Frans
Frans,
The eStreamer protocol is designed exactly for these scenarios. If the Splunk and the Sourcefire DC instances lose connectivity/communication, the event stream will pick right back up where it left off when the connectivity/comms are restored.
Frans,
The eStreamer protocol is designed exactly for these scenarios. If the Splunk and the Sourcefire DC instances lose connectivity/communication, the event stream will pick right back up where it left off when the connectivity/comms are restored.