<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Security Suite not populating in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333357#M39991</link>
    <description>&lt;P&gt;One can do that if your experiencing heavy traffic -depending on the number of devices reporting in - I have never had to go that route though. I will highly recommend using TCP rather than UDP though, as it is connection oriented rather than connection less - makes for eaiser troubleshooting too &lt;/P&gt;</description>
    <pubDate>Wed, 26 Jul 2017 16:01:37 GMT</pubDate>
    <dc:creator>klaxdal</dc:creator>
    <dc:date>2017-07-26T16:01:37Z</dc:date>
    <item>
      <title>Cisco Security Suite not populating</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333349#M39983</link>
      <description>&lt;P&gt;I've read a couple of posts/answers here.&lt;/P&gt;

&lt;P&gt;What I did.&lt;/P&gt;

&lt;P&gt;created a local directory  on the TA_cisco-asa app and copied eventtypes, transforms, and props. Upon checking on the config files, contrary to the answers on the posted questions here, they were already commented out by default. *the [source::udp::514]&lt;/P&gt;

&lt;P&gt;Upon checking on the dashboards, they were looking for eventtype=cisco-firewall&lt;/P&gt;

&lt;P&gt;checked eventtypes.conf and no cisco-firewall defined like really? why? and i thought add-ons will require minimal to no configuration already. only enabling some of the metrics.&lt;/P&gt;

&lt;P&gt;current setup is splunk listening to 514 with the sourcetype=syslog&lt;/P&gt;

&lt;P&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 06:33:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333349#M39983</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2017-07-26T06:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite not populating</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333350#M39984</link>
      <description>&lt;P&gt;Pretty sure your source type is incorrect . &lt;/P&gt;

&lt;P&gt;Check the index to ensure you are receiving events from the ASA &lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 12:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333350#M39984</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2017-07-26T12:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite not populating</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333351#M39985</link>
      <description>&lt;P&gt;Source type should be set to manual -  cisco:asa or cisco_asa  ( I forget off hand which one works ) start with cisco:asa&lt;/P&gt;

&lt;P&gt;You may also want to output the syslogs via TCP as its more reliable and configure a separate index for your Cisco products ..... see link &lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/174583/cisco-security-suite-add-on-for-cisco-asa-do-i-nee.html"&gt;https://answers.splunk.com/answers/174583/cisco-security-suite-add-on-for-cisco-asa-do-i-nee.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 12:35:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333351#M39985</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2017-07-26T12:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite not populating</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333352#M39986</link>
      <description>&lt;P&gt;Unless you make any changes to the TA/app you download from splunkbase or you add some customizations, you don't need a local directory.&lt;BR /&gt;
From the problem you explained, I believe you are looking into the dashboards in the security suite app - &lt;A href="https://splunkbase.splunk.com/app/525/"&gt;https://splunkbase.splunk.com/app/525/&lt;/A&gt;. &lt;BR /&gt;
If you check the default/eventtypes.conf - you will see the eventtype "cisco-firewall".&lt;BR /&gt;
Since you are getting the events with the source type "syslog", You can download the TA for cisco- ASA here. &lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/1620/"&gt;https://splunkbase.splunk.com/app/1620/&lt;/A&gt;. &lt;BR /&gt;
This one transforms your source type into cisco:asa which the app is looking for.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 14:58:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333352#M39986</guid>
      <dc:creator>bheemireddi</dc:creator>
      <dc:date>2017-07-26T14:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite not populating</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333353#M39987</link>
      <description>&lt;P&gt;Yes you're right. I precreated the index with the sourcetype as syslog before the integration. :))&lt;/P&gt;

&lt;P&gt;If i will have to populate the other dashboards in cisco suite, say for example the cisco esa or wsa, should I create another index and define a new port for logging as 514 is exclusively for asa?&lt;/P&gt;

&lt;P&gt;Many thanks btw, i will try this by tomorrow and will accept this answer if it works&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 15:18:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333353#M39987</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2017-07-26T15:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite not populating</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333354#M39988</link>
      <description>&lt;P&gt;No need to create another index . I have set this up many times - outputting all my CISCO devices IPS / ASA /WSA to the same index . &lt;/P&gt;

&lt;P&gt;They can use the same port however you want to be aware of the amount of traffic flow - which my require you to break out the traffic on various ports e.g. TCP 514 , TCP 515 etc and index to a common index to keep things straight ( my personal preference )  such as index=cisco &lt;/P&gt;

&lt;P&gt;You should be able to simpley change the source type on your current configuration by editing the data input to reflect cisco:asa &lt;/P&gt;

&lt;P&gt;BTW - getting the IPS data in can be a challenge due to issues with the python script and SSL  - but we can cross that bridge when you get there &lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 15:26:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333354#M39988</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2017-07-26T15:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite not populating</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333355#M39989</link>
      <description>&lt;P&gt;So meaning, i should define different ports for every new cisco device with the same index right but with different correct sourcetypes right?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 15:30:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333355#M39989</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2017-07-26T15:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite not populating</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333356#M39990</link>
      <description>&lt;P&gt;Hello, thank you for the comment.i believe klaxdal already pinpointed my problem which is the sourcetype not being defined properly. Though you're right about the local folder since i didn't change any conf files so no need for the local&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 15:36:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333356#M39990</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2017-07-26T15:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite not populating</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333357#M39991</link>
      <description>&lt;P&gt;One can do that if your experiencing heavy traffic -depending on the number of devices reporting in - I have never had to go that route though. I will highly recommend using TCP rather than UDP though, as it is connection oriented rather than connection less - makes for eaiser troubleshooting too &lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 16:01:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333357#M39991</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2017-07-26T16:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite not populating</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333358#M39992</link>
      <description>&lt;P&gt;hello, klaxdal. so I have already set the sourcetype as cisco:asa but this will only limit me to monitor the cisco:asa sourcetypes. I need all the cisco logs to automatically populate all the dashboards in this app.&lt;/P&gt;

&lt;P&gt;check this link&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/188473/what-sourcetype-should-i-set-ciscoasa-switch-data.html"&gt;https://answers.splunk.com/answers/188473/what-sourcetype-should-i-set-ciscoasa-switch-data.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;it says their that sourcetype=syslog will automatically redefined with their respective sourcetype. thoughts?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 08:03:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333358#M39992</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2017-08-01T08:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite not populating</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333359#M39993</link>
      <description>&lt;P&gt;Have you installed the other TAs required for the APP and additional source types ? &lt;/P&gt;

&lt;P&gt;I have never has to specify anything other than CISCO:ASA and the index in the UDP data setup . &lt;/P&gt;

&lt;P&gt;KL&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 16:10:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Security-Suite-not-populating/m-p/333359#M39993</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2017-08-01T16:10:53Z</dc:date>
    </item>
  </channel>
</rss>

