All Apps and Add-ons

FirePower eNcore event count drops after normal FirePower Defense Center updates

_joe
Contributor

Hello all,

I was wondering if anyone else has seen their event count drop (down to 10%?) after the FirePower team updates signatures on the Defense Center? 

In the last couple months I saw this happen twice, once I was running 'Firepower eNcore Add-On for Splunk' v4.0.7 then once when I was running 3.6.8 (I downgraded). The FirePower team says there was nothing abnormal about their update. 

I am running ~ Splunk Enterprise 8.4 

Upgrading to eNcore 4.0.9 is not an option (forwarder crashed on that version weeks on that ago, we opened a cisco TAC case and they still haven't been able to tell us what happened).

Cisco Secure eStreamer Client (f.k.a Firepower eNcore) Add-On for Splunk
https://splunkbase.splunk.com/app/3662/

 

Labels (2)
0 Karma

_joe
Contributor

Thanks vikramyadav. The only problem is I also ran into this issue on 4.0.7 and enterprise v8. I could downgrade but I hope to move back to 4.x soon after cisco resolves some of the 4.0.9 bugs (they told me they have to resolve CSCvw51040 and I might also be hitting another bug). 

0 Karma

vikramyadav
Contributor

Hi @_joe ,

I believe Cisco Secure eStreamer Client (f.k.a. eNcore) Technical Add-on for Splunk  v3.6.8 is not supported on Splunk Enterprise 8.4. And might be due to this you are facing event drop issue.

vikramyadav_0-1605987111031.png

I would recommend you to use the latest or appropriate version of the Add-on depending upon your Splunk Enterprise Version.

--------------------------------------------------------

If this helps your like will be appreciated😊



0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...