All Apps and Add-ons

How to get Cisco eStreamer for Splunk to run in Splunk 6.2?

johnbradley43
New Member

Receive error when trying to run setup - is there a simple way to fix this without modifying the config manually?

Splunk could not perform action for resource apps/local/eStreamer (404, u'Splunk cannot find "apps/local/eStreamer/setup". [HTTP 404] https://127.0.0.1:8089/servicesNS/admin/eStreamer/apps/local/eStreamer/setup; [{\'text\': "\n In handler \'localapps\': Error while fetching url=/servicesNS/nobody/eStreamer/estreamer/configuration/estreamer/?_strict=true;search=%20eai%3Aacl.app%3D%22%22%20OR%20eai%3Aacl.app%3D%22eStreamer%22", \'type\': \'ERROR\', \'code\': None}]')

0 Karma

douglashurd
Builder

while we're on the topic, is this the app you are trying to use? https://splunkbase.splunk.com/app/3662/

The older (1629) app is going to cause you nothing but problems with FP 6.x.

0 Karma

douglashurd
Builder

A new Splunk Firepower solution is now available if you are using Firepower version 6.x. You can download the new eStreamer eNcore for Splunk and the separately installable dashboard from the two links below:

eStreamer eNcore
https://splunkbase.splunk.com/app/3662/

eNcore Dashboard
https://splunkbase.splunk.com/app/3663/

It is free to use and well documented but if you would like to purchase a TAC Support service so that you can obtain installation and configuration assistance and troubleshooting you can order the software from Cisco (support obligatory with this purchase). The Product Identifier is: FP-SPLUNK-SW-K9.

Regardless of whether you take up the support option or not, updated versions will be made available to all free of charge and posted on Splunkbase as well as Cisco Downloads.

0 Karma

koshyk
Super Champion

special Thanks Doug for rewriting the TA as it is well needed. Just few suggestions
1. Can you please upload the documentation from word-document to a wiki if possible? (as attachments are not available in some of our clients offices)
2. Is there any chance to have an FMC hosted in cloud ? (i'm not an expert in FMC), but would be very good to test the TA and estreamer in development/personal laptops before trying in enterprise environments

Cheers

0 Karma

douglashurd
Builder

can you please email me directly at dohurd@cisco.com re the FMC instance you might be able to access for testing?

On the document, I can mail that to you too.

You can download the Operations Guide form the splunkbase page here too: https://splunkbase.splunk.com/app/3662/

0 Karma

ppablo
Retired

From looking at the app's page https://apps.splunk.com/app/1629/ it looks like the issue might be that only Splunk 6.0 and 6.1 are currently supported.

0 Karma

johnbradley43
New Member

Right - was wondering if there was a workaround for this and what is keeping it from working on 6.2. I'll keep researching.

Thanks

0 Karma

muralianup
Communicator

I have a 6.0 version & e-Streamer still throwing error whenever I try to go to the setup page.

0 Karma

mekozloski
New Member

Did you find anything out on this?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...