Skip to main content
Warning
This app is archived. App archiving documentation
Cisco Firepower pcap Add-on app icon

Cisco Firepower pcap Add-on

This add-on provides workflow actions for a Firepower IPS event to retrieve a pcap file or Snort rule from the Firepower Management Center (FMC). Assumes the "Cisco Firepower eStreamer eNcore Add-on for Splunk" has been installed with the event type "estreamer_ids_ips_event", and the event "host" field is the FMC. Copy "fp_pcap.cgi" and "fp_rule.cgi" from "$SPLUNK_HOME/etc/apps/TA-cisco-firepower-pcap-add-on/default/" to "/var/sf/htdocs/" on the FMC. Run command "sudo chown www:www fp_pcap.cgi fp_rule.cgi" and "sudo chmod 755 fp_pcap.cgi fp_rule.cgi".Built by D C
splunk product badge

Default Version 1.0.0

November 6, 2020

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

Rating
0
(0)

Log in to rate this app

Support
Archived Add-on

This add-on provides workflow actions for a Firepower IPS event to retrieve a pcap file or Snort rule from the Firepower Management Center (FMC). Assumes the "Cisco Firepower eStreamer eNcore Add-on for Splunk" has been installed with the event type "estreamer_ids_ips_event", and the event "host" field is the FMC. Copy "fp_pcap.cgi" and "fp_rule.cgi" from "$SPLUNK_HOME/etc/apps/TA-cisco-firepower-pcap-add-on/default/" to "/var/sf/htdocs/" on the FMC. Run command "sudo chown www:www fp_pcap.cgi fp_rule.cgi" and "sudo chmod 755 fp_pcap.cgi fp_rule.cgi".