All Apps and Add-ons

Has anyone been able to extract XFF with the estreamer or encore client?

ctrol
Engager

Has anyone been able to log the the original client ip in Sourcefire logs from traffic coming through a VIP in the eStreamer index?

We can see the original IP in the packet information in the FMC but are unable to get it to send in the logs to Splunk, all we get is the VIP ip address in the source ip field.

We have tested this on both the eStreamer app and the encore app in our instance, and original client ip is turned on in Sourcefire

Any help would be appreciated

jjoshi66
Engager

Any update on this?

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...