Skip to content
This repository has been archived by the owner on Aug 13, 2022. It is now read-only.

Latest commit

 

History

History
54 lines (27 loc) · 1.73 KB

File metadata and controls

54 lines (27 loc) · 1.73 KB

Firepower eStreamer and Splunk

Lab Objective

Create a Splunk application that visualizes threat data provided by the Firepower Management Center (FMC) using the eStreamer API.

Completion time: 45 minutes

Prerequisites

Basic understanding of Splunk and the Firepower Management Center

Basic Linux CLI knowledge

A DevNet Sandbox instance from the below link: https://devnetsandbox.cisco.com/RM/Diagram/Index/2dc005dc-a5bf-4b44-8ae2-074d61076b50?diagramType=Topology

Learning Objective

After Completing this module, you will be able to:

  • Stream events from a FMC to a Splunk instance using eStreamer

  • Create Splunk apps that can visualize the data provided by the FMC

eStreamer API

The Firepower Management Center’s (FMC) eStreamer API streams Firepower events to remote clients. Users can choose which event types they wish to stream and can stream events to multiple remote clients.

Configuring eStreamer:

  1. Navigate to the FMC UI

    1. For the DEVNET live sandbox VPN into the Sandbox and navigate to: https://10.10.20.40
  2. Log in with your username and password

  3. Navigate via the menu to: System > Integration > eStreamer

  4. In the left-hand panel select that event types shown in the screenshot below and click ‘Save’

    FMC Screenshot

  5. Click ‘Create Client’

  6. Enter the ‘Hostname’ of the remote Splunk server that will receive the events

    FMC Screenshot

  7. Click ‘Save’ to create the new Client

  8. Once the client configuration is saved, click on the download FMC Screenshot icon to obtain the client certificate required to connect via the eNcore eStreamer client