Splunk Search

Sourcefire estreamer

timlaw71
Loves-to-Learn Lots

I'm trying to get estreamer working on splunk. I have downloaded the splunk app and configured the files in the app according to the README. The ssl_test.pl script works but when I run the estreamer.py script I get
Traceback (most recent call last):
File "./estreamer.py", line 10, in
APP_PATH = os.path.join(os.environ["SPLUNK_HOME"], 'etc', 'apps', 'Sourcefire')
File "/usr/lib64/python2.6/UserDict.py", line 22, in getitem
raise KeyError(key)
KeyError: 'SPLUNK_HOME'
Any help would be appreciated.

Thanks,
Tim

0 Karma

edbolton
Explorer

You need to export the envrionment variable SPLUNK_HOME in your shell.

KeyError: 'SPLUNK_HOME'

0 Karma
Get Updates on the Splunk Community!

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...