Splunk® Supported Add-ons

Splunk Add-on for Cisco FireSIGHT

Release notes for the Splunk Add-on for Cisco FireSIGHT

Version 3.3.2 of the Splunk Add-on for Cisco FireSIGHT is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 7.0.x, 7.1.x, 7.2.x, 7.3.x, 8.0.x
CIM 4.11
Platforms Platform independent
Vendor Products Cisco FireSIGHT Management Center version 5 eStreamer output, Sourcefire Defense Center version 4.X syslog or eStreamer output, Open-source Snort version 2.x

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

Fixed issues

Version 3.3.2 of the Splunk Add-on for Cisco FireSIGHT has the following fixed issues.

Date resolved Ticket number Description
2016-04-21 ADDON-8918 "app_proto" should be mapped to "app" field in Network Traffic CIM data model for event type cisco_sourcefire.
2016-04-21 ADDON-8749 Refine "signature" field definition for source type cisco:sourcefire.
2016-04-20 ADDON-8902 The "severity" field in source type cisco:sourcefire has multiple values.
2016-04-18 ADDON-8731 vendor_action "Threat Detected in Exclusion" has no action value in cisco_sourcefire_malware_action.csv lookup file.
2016-03-14 ADDON-7954 Performance issues in Splunk Enterprise Security related to tag expansions.
2016-03-14 ADDON-8204 Update definition of event type "cisco_sourcefire" as "Malware Clould Lookup" is actually a vendor_action value.

Known issues

Version 3.3.2 of the Splunk Add-on for Cisco FireSIGHT has the following reported known issues.

Date Ticket number Description
2015-11-10 ADDON-6381 eStreamer malware data is incorrectly tagged.

Third-party software attributions

Version 3.3.2 of the Splunk Add-on for Cisco FireSIGHT does not incorporate any third-party software or libraries.

Last modified on 04 January, 2021
Source types for the Splunk Add-on for Cisco FireSIGHT   Release history for the Splunk Add-on for Cisco FireSIGHT

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters