Getting Data In

Getting data from Cisco Firepower WITHOUT Firepower Management Console (FMC)

ari-001
Explorer

Hello, 

Im a splunk newbie, we dont have FMC module. How do I send logs to Splunk without using FMC ? I only have access to Firepower Device Manager. 

Labels (2)

ari-001
Explorer

yes, I have looked into these docs. The main problem is that I do NOT have FMC. Is there a way that I can integrate Firepower to Splunk WITHOUT the need for FMC. 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

may we know if you checked the user guide:

https://www.cisco.com/c/en/us/td/docs/security/firepower/splunk/Cisco_Firepower_App_for_Splunk_User_...

https://splunkbase.splunk.com/app/4388/

 

 

(i received the 100 karma points giver badge.. have you?)

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...