All Apps and Add-ons

eStreamer logs from Active - Passive Sourcefire setup

lakshman239
SplunkTrust
SplunkTrust

We have Sourcefire/Firesight 6.x deployed in active-passive setup. I have 2 splunk servers (both running on splunk 6.x on linux) , one connected to active and another connected to passive, using the encore add-on and certs.

I now receive events/logs from both the active and passive server, essentially duplicating the events. What can be done at the sourcefire or encore config to get only logs/events from active server? reading the operations manual and other posts, Dougless Hurd seems to suggest a support ticket can be raised to address this via CLI and/or some features coming in future version.

Could yous pls advise the way forward to enable us to receive logs only from active server in the above setup? [ apart from manually configuring splunk to read logs/events from active server]. Is this feature is not available, is that planned in future release/timescales?

Thanks

satyajitjem
New Member

I think you need to this setup from Universal forwarder end !Please check that settings in your Env first followed by Splunk Config. (what is the setup & share the extracted files)

0 Karma

DATEVeG
Path Finder

We also do have that kind of setup:
2x fmpc
2x universal forwarder

In case of a failover in fpmc, we manually switch the ip adress configured in encore.

The universal forwarder uses keepalived to manage one virtual ha ip address. Only the forwarder with the active ha ip address will run encore.

A solution where encore can support multiple fpmc systems and perform deduplication would be really great.

0 Karma

lakshman239
SplunkTrust
SplunkTrust

Thx DateVeG. At the moment, I enable the TA-eStream to manage fail-over . Yes, getting this in the product would be ideal.

0 Karma

xavierashe
Contributor

We have the same active/passive setup, and we are getting the logs from the management server, not the sensors themselves. Is that an option for you?

0 Karma

lakshman239
SplunkTrust
SplunkTrust

Thx Xav. We don't have the route via mgmt sever. let me explore that.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...