Splunk Enterprise Security

How to connect multiple instances of Cisco Firepowers to Splunk using eStreamer enCore

sshukla2505
New Member

Hi,
So, I have got 2 instances of Cisco Firepower management centers. I need to connect these 2 FMCs to our eStreamer eNcore Add-on for Splunk. I have gone through almost all of the answers related to this issue, but couldn't find an accepted/working resolution.

In our infra, the "client.pkcs12" is same for both the FMCs; thereby, implying that I can use the same file to connect to both the FMCs. However, the configuration set-up of "eStreamer eNcore Add-On" restricts me to enter only 1 FMC's IP address.
Question-1: Is there way I can enter multiple FMC's IP addresses ......or
Question-2: Is there a way that we can configure our Splunk forwarder to receive logs from 2 different FMCs.

0 Karma

danbrook
Explorer

Similar setup for me but I have 1 FMC and 1 Indexer. I have multiple domain on the FMC and am trying to send logs to seperate indexes. Can the same client.pkcs12 file and password be used under each domain?

0 Karma

abwe
Loves-to-Learn Lots

@nrduren1115 can you provide the way?

0 Karma

ahmadjabr
Engager

could you give us how did you do it?
,how did you do it??

0 Karma

lakshman239
Influencer

I think the approach they have taken is to have instances of the same add-on [ you need to have diff names though] and then configure them with diff/same pkcs file to pull data from the FMC. This would work as splunk will see them as two diff data source]. You would need to ensure local/apps.conf, inputs.conf are updated to have unique app name and path (monitor stanza) for the data files to be ingested to splunk.

0 Karma

abwe
Loves-to-Learn Lots

@lakshman239 We tried that but it failed to give a result, have you tried something like that before???

0 Karma

lakshman239
Influencer

nope. haven't tried.

0 Karma

nrduren1115
Explorer

We recently did this and have it working. You can clone the app and then set up duplicate file and script inputs for the second FMC.

alt text

0 Karma

cemx11
New Member

Hello,

How do you clone the app? Just copy/paste the folders?

0 Karma

czsmunt
Observer

Did you ever figure this out?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...