Splunk Enterprise Security

Cisco eStreamer for Splunk: How to resolve error "Problems starting the eStreamer client"?

rmf185039
New Member

Hi everyone!

I attempted to follow the other "Problems starting the eStreamer client" post but was unable to get it running. Unfortunately, it isn't giving me any specific reason why it's failing. I am currently running the Cisco eStreamer for Splunk app from a syslog-ng server set up as a heavy forwarder. I have tried to reissue the cert both with and without a password, and modify the permissions on the estreamer.conf file as suggested. eStreamer_client.pl runs without an issue. But client_check.py continues to throw an error. Does anyone have any suggestions?

$ ./estreamer_client.pl
Usage:  estreamer_client.pl [options]
Options:
        [-c]onfig=<config filename>
        [-l]ogfile=<log filename>
        [-t]est
        [-d]aemon

bin]$ ./client_check.py
event_sec=1486582853 status_id=-1 status="ERROR: Problems starting the eStreamer client ()"

Thanks,
Ryan

0 Karma

douglashurd
Builder

A new Splunk Firepower solution is now available if you are using Firepower version 6.x. You can download the new eStreamer eNcore for Splunk and the separately installable dashboard from the two links below:

eStreamer eNcore
https://splunkbase.splunk.com/app/3662/

eNcore Dashboard
https://splunkbase.splunk.com/app/3663/

It is free to use and well documented but if you would like to purchase a TAC Support service so that you can obtain installation and configuration assistance and troubleshooting you can order the software from Cisco (support obligatory with this purchase). The Product Identifier is: FP-SPLUNK-SW-K9.

Regardless of whether you take up the support option or not, updated versions will be made available to all free of charge and posted on Splunkbase as well as Cisco Downloads.

0 Karma

douglashurd
Builder

what does it look like in the splunk ui? Does the dashboard there give any other errors? Do you have the right Perl Libraries installed?

0 Karma

rmf185039
New Member

just a bunch of 0's in the dashboards, I did a "cpan -l" to list all modules and I was missing IO::Socket:SSL but I just installed it and disabled and re-enabled the app but still no luck when I run client_check.py.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...