All Apps and Add-ons

Estreamer not mapping the src_ip or dest_ip

clozach
Path Finder

Hi all,

Weird issue here where all fields are being mapped besides possibly the most important ones (src_ip and dest_ip). Not sure what I could do to make these field appear, so I thought I'd post it here. Let me know if you have any suggestions.

0 Karma

lakshman239
SplunkTrust
SplunkTrust

I assume you are using https://splunkbase.splunk.com/app/1808 and https://splunkbase.splunk.com/app/3662/ . The later collects the data [ has CIM fields as well] and we will need following rename in local/props.conf on the later app to use cisco:sourcefire sourcetypes and CIM fields. You will then have src/src_ip/dest/dest_ip. Additionally, if you know your source and dest are IPs, you can alias or coalesce them to map to src_ip and dest_ip.
//props.conf

[cisco:estreamer:data]
rename = cisco:sourcefire
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...