Hey all, does anyone know of a good set of instructions for getting the Splunk for Sourcefire app receiving data from a Sourcefire Defense Center (im running a DC 750). I got the app installed on Splunk, I have what I think is the proper configuration for estreamer, but it's not working. I have verified that the DC is sending SYSLOG events to Splunk so I know it's "talking", but I can't get anything into the Splunk for Sourcefire App.
I edited the config file with the ip of my DC as well. Still nothing.
Any thoughts? I'm running Splunk on Windows. I have Perl and Python installed.
THe estreamer app is only compatible with Unix platforms
Is this answer, "run Splunk on Linux"?