Good Afternoon,
We are attempting to get our Stealthwatch data into Splunk. We are in Cloud 8.1 one so the only Add-on available is the Technology add-on for Cisco Stealthwatch from a 3rd party. Technology Add-on for Cisco Stealthwatch Data Exporter | Splunkbase
We have installed the Data Exporter on our Flow Collector and confirmed that Docker Container is working. Based on the Data Exporter documentation I installed a Get-Flows script that is pulling data but I am not sure it is pulling everything and the format is clunky.
I am curious if anyone has experience with getting Stealthwatch data into Splunk Cloud with this App and what is the best way to do it.