Getting Data In

CiscoSecurityCloud TA 3.6.7 -eStreamer ingestion falling behind by several hours under high log volume from a single FMC

refahiati
Explorer
We are using the CiscoSecurityCloud TA 3.6.7 to ingest firewall events via eStreamer from a single FMC that has 5 firewall groups connected to it. We cannot separate these groups across multiple FMC instances as they are all managed by one FMC. Event types we collect are ConnectionEvent, IntrusionEvent, and FileEvent, with import_time_range set to from_now.

The ingestion is consistently falling behind real-time, and the delay grows with log volume. During peak traffic hours the lag reaches several hours.

We already verified the eStreamer TCP connection to FMC is stable with no disconnects or SSL errors, and the delay is directly correlated with traffic volume — low traffic gives around 40 minutes delay while high traffic pushes it to several hours.

Our questions are: Is this a known limitation when a single FMC manages multiple high-traffic firewall groups over one eStreamer connection? Are there any tuning options in CiscoSecurityCloud TA 3.6.7 to improve throughput such as chunk size or socket buffer settings? And is there any recommended workaround for this scenario where splitting the FMC is not an option?

Any guidance from the community or Cisco/Splunk engineers would be greatly appreciated.
Cisco Security Cloud
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...