Getting Data In

Cisco Secure eStreamer Client Autolookup estreamer_fw_action commented out

elee_splunk
Loves-to-Learn Everything

After updating our TA we realized the action field autolookup wasn't working anymore. Digging through the TA I see in the props.conf the autolookup "LOOKUP-estreamer_fw_action" is commented out. Is there a reason this was done?

 

@douglashurd - Can you please advise. Thanks!

Labels (1)
0 Karma

douglashurd
Builder

Thanks for the question.  A few questions:

What event type did you lose the field in?

What version of the TA are you using?

Please email the details to encore-community@cisco.com for a slight quicker response.

 

Thanks,

 

Doug

0 Karma

elee_splunk
Loves-to-Learn Everything

I lost action field in the firewall rule logging cisco:estreamer:data. There is a field called fw_rule_action but there is supposed to be an autolookup that translates the fw_rule_action to action. 

I am using 4.6.0 but I downloaded and check 4.6.1 and 4.6.2 and all of them have the line for the autolookup commented out.

I have emailed encore-community@cisco.com for further support. 

 

Thanks!

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...