All Apps and Add-ons

Ingesting logs from two eStreamer nodes

gcusello
SplunkTrust
SplunkTrust

Hi at all,
I have to ingest logs from two eStreamer nodes.
I'm already ingesting logs from the first one using eStreamer App 2.2.2, how can I have logs from the second one?

Could it be a solution to install two instances of the same app?
each one could take logs from one eStreamer node and both write on the same index, so using one App instance I could see all the logs.
I don't know if this could be a good solution.

Thank you in advance.

Bye.
Giuseppe

0 Karma
1 Solution

micahkemp
Champion

I've looked into this, and unfortunately the only answer (for this version, which works for Firepower 5) is to run the app on multiple forwarders, one forwarder per eStreamer node.

The good news is that this wouldn't prevent the events from going into the same index.

View solution in original post

0 Karma

micahkemp
Champion

I've looked into this, and unfortunately the only answer (for this version, which works for Firepower 5) is to run the app on multiple forwarders, one forwarder per eStreamer node.

The good news is that this wouldn't prevent the events from going into the same index.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Thanks micahkemp,
Do you suggest to get data from two nodes in the same index?

is it possible to recognize event nodes?

Bye.
Giuseppe

0 Karma

douglashurd
Builder

If you move to version 6.x of firepower you will be best served to use the new TA: https://splunkbase.splunk.com/app/3662/

rafeeqsid25
New Member

https://splunkbase.splunk.com/app/3662/ this add-on is not suppported on Splunk Windows Environment.

0 Karma

micahkemp
Champion

The events should show the correct sensor that matched the traffic detected, but I'm not sure if the event would indicate which Firepower device the event was pulled over eStreamer from. That might be in the host field, but I don't have any eStreamer devices to test with.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Ok, I'll test it.
Thank you.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...