An engineer is troubleshooting an eStreamer integration between Cisco FMC and a third-party SIEM. The SIEM client script successfully connects to the FMC eStreamer port (8302), but no events are being received. Where should the engineer verify the eStreamer client certificate and access rights on the FMC?
Trap 1: Modify the Access Control Policy advanced settings to allow…
eStreamer traffic terminates on the FMC management plane, not the data plane inspected by Snort.
Trap 2: Configure the external Automation policy under Objects > Object…
There is no Automation policy object for eStreamer configuration; it is managed centrally under System Integration.
- A
Navigate to System > Integration > eStreamer on the FMC to manage client certificates and allowed IP addresses.
The eStreamer management interface under System > Integration > eStreamer is where client certificates are generated and connection rights are granted.
- B
Modify the Access Control Policy advanced settings to allow eStreamer traffic through the Snort inspection engine.
Why wrong: eStreamer traffic terminates on the FMC management plane, not the data plane inspected by Snort.
- C
Configure the external Automation policy under Objects > Object Management > eStreamer.
Why wrong: There is no Automation policy object for eStreamer configuration; it is managed centrally under System Integration.
- D
Navigate to Devices > Platform Settings > Syslog and add the SIEM IP address.
This option is incorrect because syslog platform settings are for standard syslog forwarding, whereas eStreamer uses port 8302 and dedicated certificates.