<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cisco security suite setup bug? in Security</title>
    <link>https://community.splunk.com/t5/Security/cisco-security-suite-setup-bug/m-p/346777#M13169</link>
    <description>&lt;P&gt;I was using the overview dashboard.  After I posted this, I realized I should've been more clear.  I like the look and feel of the overview dashboard.  I can see the network security/firewall event search dashboard be populated.  &lt;/P&gt;

&lt;P&gt;For example, I see the search strings used in the map.  How would I get the ASA firewall data to the overview portion?  Cisco-security-events is the eventtype the map is looking for.  Am I looking for a way that the eventtype is changed or am I needing to change what eventtype the map is looking for?  &lt;/P&gt;</description>
    <pubDate>Wed, 18 Apr 2018 12:53:21 GMT</pubDate>
    <dc:creator>djhoskins</dc:creator>
    <dc:date>2018-04-18T12:53:21Z</dc:date>
    <item>
      <title>cisco security suite setup bug?</title>
      <link>https://community.splunk.com/t5/Security/cisco-security-suite-setup-bug/m-p/346775#M13167</link>
      <description>&lt;P&gt;I have recently set up CIsco Security suite and I'm confused as to what happened in the setup.  I have an ASA firewall sending data to splunk.  During the setup, it asked which type of firewall logs were being used, I selected ASA (triple checked).  I see that I have files coming in from the ASA (using the search app) but are not coming in on the dashboard.  When I hover over the yellow ! I see that it is looking for eventtype: cisco_esa_authentication, esa_email and esa_proxy.  Did I miss a step?  It seemed pretty straight forward.  I do not have the esa add-on installed, but do have the asa add-on installed.  Should I change the eventtype in /apps/Splunk_ciscoSecuritySuite/default/eventtypes.conf?   I see the eventtype of my incoming data is cisco_connection, perhaps that is something I need to look in to as well.   Please advise.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:07:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/cisco-security-suite-setup-bug/m-p/346775#M13167</guid>
      <dc:creator>djhoskins</dc:creator>
      <dc:date>2020-09-29T19:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: cisco security suite setup bug?</title>
      <link>https://community.splunk.com/t5/Security/cisco-security-suite-setup-bug/m-p/346776#M13168</link>
      <description>&lt;P&gt;Which dashboard you are looking for ASA data?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 05:51:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/cisco-security-suite-setup-bug/m-p/346776#M13168</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-04-18T05:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: cisco security suite setup bug?</title>
      <link>https://community.splunk.com/t5/Security/cisco-security-suite-setup-bug/m-p/346777#M13169</link>
      <description>&lt;P&gt;I was using the overview dashboard.  After I posted this, I realized I should've been more clear.  I like the look and feel of the overview dashboard.  I can see the network security/firewall event search dashboard be populated.  &lt;/P&gt;

&lt;P&gt;For example, I see the search strings used in the map.  How would I get the ASA firewall data to the overview portion?  Cisco-security-events is the eventtype the map is looking for.  Am I looking for a way that the eventtype is changed or am I needing to change what eventtype the map is looking for?  &lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 12:53:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/cisco-security-suite-setup-bug/m-p/346777#M13169</guid>
      <dc:creator>djhoskins</dc:creator>
      <dc:date>2018-04-18T12:53:21Z</dc:date>
    </item>
  </channel>
</rss>

