Splunk Enterprise Security

Cisco eStreamer for Splunk: How to resolve error "Problems starting the eStreamer client"?

rmf185039
New Member

Hi everyone!

I attempted to follow the other "Problems starting the eStreamer client" post but was unable to get it running. Unfortunately, it isn't giving me any specific reason why it's failing. I am currently running the Cisco eStreamer for Splunk app from a syslog-ng server set up as a heavy forwarder. I have tried to reissue the cert both with and without a password, and modify the permissions on the estreamer.conf file as suggested. eStreamer_client.pl runs without an issue. But client_check.py continues to throw an error. Does anyone have any suggestions?

$ ./estreamer_client.pl
Usage:  estreamer_client.pl [options]
Options:
        [-c]onfig=<config filename>
        [-l]ogfile=<log filename>
        [-t]est
        [-d]aemon

bin]$ ./client_check.py
event_sec=1486582853 status_id=-1 status="ERROR: Problems starting the eStreamer client ()"

Thanks,
Ryan

0 Karma

douglashurd
Builder

A new Splunk Firepower solution is now available if you are using Firepower version 6.x. You can download the new eStreamer eNcore for Splunk and the separately installable dashboard from the two links below:

eStreamer eNcore
https://splunkbase.splunk.com/app/3662/

eNcore Dashboard
https://splunkbase.splunk.com/app/3663/

It is free to use and well documented but if you would like to purchase a TAC Support service so that you can obtain installation and configuration assistance and troubleshooting you can order the software from Cisco (support obligatory with this purchase). The Product Identifier is: FP-SPLUNK-SW-K9.

Regardless of whether you take up the support option or not, updated versions will be made available to all free of charge and posted on Splunkbase as well as Cisco Downloads.

0 Karma

douglashurd
Builder

what does it look like in the splunk ui? Does the dashboard there give any other errors? Do you have the right Perl Libraries installed?

0 Karma

rmf185039
New Member

just a bunch of 0's in the dashboards, I did a "cpan -l" to list all modules and I was missing IO::Socket:SSL but I just installed it and disabled and re-enabled the app but still no luck when I run client_check.py.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...