<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Firewall Add-on - empty results in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firewall-Add-on-empty-results/m-p/95153#M6488</link>
    <description>&lt;P&gt;i notice this too but my data is from v8.2, must be an extraction issue in the base app?&lt;/P&gt;</description>
    <pubDate>Wed, 04 Apr 2012 18:12:06 GMT</pubDate>
    <dc:creator>cvajs</dc:creator>
    <dc:date>2012-04-04T18:12:06Z</dc:date>
    <item>
      <title>Cisco Firewall Add-on - empty results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firewall-Add-on-empty-results/m-p/95150#M6485</link>
      <description>&lt;P&gt;In Security Suite under Firewall &amp;gt; Overview search shows no results, viewing the Inspect shows search eventtype="cisco_firewall" | bin _time span=5m | stats count by eventtype, src_ip, dest_ip, host,log_level_desc,event_desc, _time&lt;/P&gt;

&lt;P&gt;If I remove each transform filter one at a time I find that neither log_level_desc or event_desc will return results, as if they do not exist in the indexed data. If I remove them both then results are displayed.&lt;/P&gt;

&lt;P&gt;Where do I start looking?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:31:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firewall-Add-on-empty-results/m-p/95150#M6485</guid>
      <dc:creator>ahammond</dc:creator>
      <dc:date>2020-09-28T11:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firewall Add-on - empty results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firewall-Add-on-empty-results/m-p/95151#M6486</link>
      <description>&lt;P&gt;if its newer ASA then maybe you need to fix the regex for this source type&lt;BR /&gt;
see &lt;A href="http://splunk-base.splunk.com/answers/42936/cisco-asa-logging-format-change"&gt;http://splunk-base.splunk.com/answers/42936/cisco-asa-logging-format-change&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2012 01:45:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firewall-Add-on-empty-results/m-p/95151#M6486</guid>
      <dc:creator>cvajs</dc:creator>
      <dc:date>2012-03-17T01:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firewall Add-on - empty results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firewall-Add-on-empty-results/m-p/95152#M6487</link>
      <description>&lt;P&gt;My Sourcetype is 'cicso__asa' after fixing the regex, but in "Cisco Firewall overview" for example the field event_desc shows somethin like this: &lt;/P&gt;

&lt;P&gt;\"Deny protocol src [interface_&lt;EM&gt;name:source&lt;/EM&gt;&lt;EM&gt;address/source_port] dst interface&lt;/EM&gt;&lt;STRONG&gt;name:dest_address/dest_port [type {string}, code {code}] by access&lt;/STRONG&gt;&lt;STRONG&gt;group acl&lt;/STRONG&gt;ID\"&lt;/P&gt;

&lt;P&gt;The other fields get extracted correctly. Perhaps someone has a hint?&lt;BR /&gt;
Where ist the field event_desc defined? Can i manually edit it?&lt;BR /&gt;
Thanks in advance&lt;/P&gt;

&lt;P&gt;Bpad&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:37:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firewall-Add-on-empty-results/m-p/95152#M6487</guid>
      <dc:creator>bpad</dc:creator>
      <dc:date>2020-09-28T11:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firewall Add-on - empty results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firewall-Add-on-empty-results/m-p/95153#M6488</link>
      <description>&lt;P&gt;i notice this too but my data is from v8.2, must be an extraction issue in the base app?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Apr 2012 18:12:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firewall-Add-on-empty-results/m-p/95153#M6488</guid>
      <dc:creator>cvajs</dc:creator>
      <dc:date>2012-04-04T18:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firewall Add-on - empty results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firewall-Add-on-empty-results/m-p/95154#M6489</link>
      <description>&lt;P&gt;Mine is also v8.2. What Versions are other people using? This ASA plugin is great and i hope i someone can help to fix this?!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2012 07:24:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-Firewall-Add-on-empty-results/m-p/95154#M6489</guid>
      <dc:creator>bpad</dc:creator>
      <dc:date>2012-04-05T07:24:27Z</dc:date>
    </item>
  </channel>
</rss>

