Deployment Architecture

How do you set up forwarding from Cisco's Firepower Event Streamer (eStreamer) to Splunk Cloud?

New Member

I have set up a TCP connection from Splunk to Cisco's Firepower eStreamer. I am trying to figure out how to best forward events from Firepower to Splunk cloud. My idea was to install a heavy forwarder first, connect that through a TCP connection to firepower, then filter on the heavy forwarder and send to Splunk.

After connecting the heavy forwarder to Firepower I don't see any events being generated. Any tips on trouble shooting or is there a better way to do this?

0 Karma


Hi Dijanad,
did you followed the instructions ( )?
because there's a perl client to enable and configure to extract data.

About the idea to use an Heavy Forwarder to filter and route data to Splunk Cloud, this is a best practice.

In addition, remember that you need of an Heavy Forwarder for each eStreamer node.


0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...