All Apps and Add-ons

splunk sourcefire connector app is not reporting logs .

Kaushikkatta03
Explorer

Hi ,

I have issue with splunk sourcefire connector app , it is conifigured on one of the splunk Heavy forwarder . it was working upto 4 th jan . I had tried resetting the connector and also restarted services of splunk if that might help but it didn't .
below is the configuration local from the app.

estreamer.conf
[estreamer]
changed = 0
pkcs12_password = XXXXXX
client_disabled = 0
log_extra_data = 1
log_metadata = 1
pkcs12_file = /opt/splunk/etc/apps/sourcefire/local/XX.XX.XXX.pkcs12
server = XX.XX.XX.XXX
watch = 1
debug = 1

/app.conf

Autogenerated file

[install]
state = enabled
is_configured = 1

props.conf
[sourcefire:network:ids]
TZ = GMT

0 Karma

att35
Builder

Hi,

From the name, it looks like you are using the old eStreamer app. If on FMC Version 6.X, you might want to check out the newer eNcore app for Splunk. https://splunkbase.splunk.com/app/3662/

~ Abhi

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...