<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco firewall logging in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-firewall-logging/m-p/67348#M13541</link>
    <description>&lt;P&gt;Splunk Team,&lt;/P&gt;

&lt;P&gt;I'm looking for log management/application profiling from Cisco ASA Firewall. &lt;BR /&gt;
On Firewall, syslog-udp/514 is enabled towards splunk server whereas Syslog id - 106100 is disabled for all firewall policies. &lt;/P&gt;

&lt;P&gt;Currently, threat-detection is also disabled. &lt;/P&gt;

&lt;P&gt;What do I need to get application profiling ( like total hits per ACL) working. &lt;/P&gt;

&lt;P&gt;Thanks &lt;BR /&gt;
~rk&lt;/P&gt;</description>
    <pubDate>Tue, 30 Aug 2011 22:39:26 GMT</pubDate>
    <dc:creator>rkarnani</dc:creator>
    <dc:date>2011-08-30T22:39:26Z</dc:date>
    <item>
      <title>Cisco firewall logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-firewall-logging/m-p/67348#M13541</link>
      <description>&lt;P&gt;Splunk Team,&lt;/P&gt;

&lt;P&gt;I'm looking for log management/application profiling from Cisco ASA Firewall. &lt;BR /&gt;
On Firewall, syslog-udp/514 is enabled towards splunk server whereas Syslog id - 106100 is disabled for all firewall policies. &lt;/P&gt;

&lt;P&gt;Currently, threat-detection is also disabled. &lt;/P&gt;

&lt;P&gt;What do I need to get application profiling ( like total hits per ACL) working. &lt;/P&gt;

&lt;P&gt;Thanks &lt;BR /&gt;
~rk&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2011 22:39:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-firewall-logging/m-p/67348#M13541</guid>
      <dc:creator>rkarnani</dc:creator>
      <dc:date>2011-08-30T22:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco firewall logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-firewall-logging/m-p/67349#M13542</link>
      <description>&lt;P&gt;you may be interested in the Splunk for Cisco Firewalls add-on:&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/apps/22303/splunk-for-cisco-firewalls"&gt;http://splunk-base.splunk.com/apps/22303/splunk-for-cisco-firewalls&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;which is part of the Splunk for Cisco Security Suite:&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/apps/22300/cisco-security-suite"&gt;http://splunk-base.splunk.com/apps/22300/cisco-security-suite&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2011 23:01:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-firewall-logging/m-p/67349#M13542</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2011-08-30T23:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco firewall logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-firewall-logging/m-p/67350#M13543</link>
      <description>&lt;P&gt;+1 on the already-built apps.  They may not have exactly the view you're looking for, but they may have a starting point you can more quickly adapt from.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2011 23:04:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-firewall-logging/m-p/67350#M13543</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2011-08-30T23:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco firewall logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-firewall-logging/m-p/67351#M13544</link>
      <description>&lt;P&gt;Thanks Piebob ! &lt;BR /&gt;
I have installed Cisco Firewall add-on. &lt;BR /&gt;
Although I haven't yet enabled syslog forwarding to splunk servers, the question is will it get all information for &lt;EM&gt;allowed&lt;/EM&gt; firewall polices also ? &lt;/P&gt;

&lt;P&gt;~rk &lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2011 13:40:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-firewall-logging/m-p/67351#M13544</guid>
      <dc:creator>rkarnani</dc:creator>
      <dc:date>2011-08-31T13:40:28Z</dc:date>
    </item>
  </channel>
</rss>

