I have set up a TCP connection from Splunk to Cisco's Firepower eStreamer. I am trying to figure out how to best forward events from Firepower to Splunk cloud. My idea was to install a heavy forwarder first, connect that through a TCP connection to firepower, then filter on the heavy forwarder and send to Splunk.
After connecting the heavy forwarder to Firepower I don't see any events being generated. Any tips on trouble shooting or is there a better way to do this?
Hi Dijanad,
did you followed the instructions ( https://splunkbase.splunk.com/app/1629/#/details )?
because there's a perl client to enable and configure to extract data.
About the idea to use an Heavy Forwarder to filter and route data to Splunk Cloud, this is a best practice.
In addition, remember that you need of an Heavy Forwarder for each eStreamer node.
Bye.
Giuseppe