All Apps and Add-ons

Splunk for eStreamer

j_greg
New Member

Configured the eStreamer app in Splunk with no issues. Had to load one perl module then usage options presented themselves. Cert is copied over. Verified port open. I'm getting no logs from sourcefire. In addition, there is no log generated to see what is not working. Can I get direction to start troubleshooting this?

0 Karma

TobiasBoone
Communicator

We would love to see windows support for this app. At least if we could get the streamer to collect data on it we could manually ferret through the data.

0 Karma

cgrady_sf
Path Finder

What do the client status messages indicate? Have you enabled verbose logging on the client (done through Settings), to generate a log file in $APP_PATH/bin/estreamer_debug.log? Both of these can help with troubleshooting.

Make sure you're on the latest version (1.0.5) to be able to take advantage of the verbose logging and more detailed client status messages.

0 Karma

cgrady_sf
Path Finder

Actually, the problem is more than likely the fact that it's a Windows install. I have only ever done dev and testing against Unix platforms. I guess I need to update the app description to make this clear. I apologize for the trouble and time spent. I'll look into Windows support for future versions.

j_greg
New Member

Splunk is installed on D of a windows OS. I was able to add python path entries in the system variables pointing to it's location. When I run client_check.py, I now get event_sec=1394810177 status_id=-1 status="ERROR: The app has not yet been setup.

0 Karma

cgrady_sf
Path Finder

What is the client status message?

Keep in mind you will need to stop and restart the client every time setting changes are made. I know this isn't clear in the current version, but I'm trying to make it more clear in future versions.

0 Karma

j_greg
New Member

Thanks for responding. Verbose logging is set. There is no created log $APP_PATH/bin/estreamer_debug.log. I'm on 1.0.5.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...