<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get Cisco App working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79663#M16360</link>
    <description>&lt;P&gt;Here are some troubleshooting tips:&lt;/P&gt;

&lt;P&gt;-- Windows Firewall&lt;/P&gt;

&lt;P&gt;Make sure that if you installed Splunk on a Windows box that the Windows firewall is not blocking UDP 514. &lt;/P&gt;

&lt;P&gt;-- Firewall&lt;/P&gt;

&lt;P&gt;Make sure that when you setup syslog that the destination ip address for the syslog traffic is the Splunk server&lt;/P&gt;

&lt;P&gt;-- Restart Splunk&lt;/P&gt;

&lt;P&gt;Make sure that you restart the Splunk processes/services when you install the Cisco Security Suite. &lt;/P&gt;</description>
    <pubDate>Wed, 29 Feb 2012 22:10:42 GMT</pubDate>
    <dc:creator>tgow</dc:creator>
    <dc:date>2012-02-29T22:10:42Z</dc:date>
    <item>
      <title>How to get Cisco App working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79658#M16355</link>
      <description>&lt;P&gt;I've installed the Cisco Firewalls app. My colleague has pointed the firewall to the splunk server:port. There is no option to start the app and there appears to be no logging taking place. How do I get this working?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2012 19:10:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79658#M16355</guid>
      <dc:creator>rblalock</dc:creator>
      <dc:date>2012-02-27T19:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Cisco App working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79659#M16356</link>
      <description>&lt;P&gt;Do you have setup an data input for syslog (udp(514)?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2012 19:58:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79659#M16356</guid>
      <dc:creator>Spelunke</dc:creator>
      <dc:date>2012-02-27T19:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Cisco App working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79660#M16357</link>
      <description>&lt;P&gt;Yes. (message padding)&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2012 20:01:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79660#M16357</guid>
      <dc:creator>rblalock</dc:creator>
      <dc:date>2012-02-27T20:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Cisco App working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79661#M16358</link>
      <description>&lt;P&gt;Make sure that you install the Cisco Security Suite first. &lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/apps/22300/cisco-security-suite"&gt;http://splunk-base.splunk.com/apps/22300/cisco-security-suite&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you have already created the data input then just save the configuration page with the defaults. &lt;/P&gt;

&lt;P&gt;Now you will need to restart Splunk from either the Manager or from the command line.&lt;/P&gt;

&lt;P&gt;The Cisco for Firewall app needs the default dashboards that are shipped with the Cisco Security Suite. &lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2012 20:29:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79661#M16358</guid>
      <dc:creator>tgow</dc:creator>
      <dc:date>2012-02-27T20:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Cisco App working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79662#M16359</link>
      <description>&lt;P&gt;Installed the Cisco security suite, and it appears to be working. But I don't see my firewall anywhere. It could be that it simply is not generating traffic. (Set to logging level "Warnings") But shouldn't I at least be able to see my firewall listed somewhere?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2012 13:11:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79662#M16359</guid>
      <dc:creator>rblalock</dc:creator>
      <dc:date>2012-02-28T13:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Cisco App working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79663#M16360</link>
      <description>&lt;P&gt;Here are some troubleshooting tips:&lt;/P&gt;

&lt;P&gt;-- Windows Firewall&lt;/P&gt;

&lt;P&gt;Make sure that if you installed Splunk on a Windows box that the Windows firewall is not blocking UDP 514. &lt;/P&gt;

&lt;P&gt;-- Firewall&lt;/P&gt;

&lt;P&gt;Make sure that when you setup syslog that the destination ip address for the syslog traffic is the Splunk server&lt;/P&gt;

&lt;P&gt;-- Restart Splunk&lt;/P&gt;

&lt;P&gt;Make sure that you restart the Splunk processes/services when you install the Cisco Security Suite. &lt;/P&gt;</description>
      <pubDate>Wed, 29 Feb 2012 22:10:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79663#M16360</guid>
      <dc:creator>tgow</dc:creator>
      <dc:date>2012-02-29T22:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Cisco App working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79664#M16361</link>
      <description>&lt;P&gt;Doh windows firewall was the solution for us on why this wasnt working. I even installed MS Net mon and was seeing traffic on the interface.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2012 22:14:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Cisco-App-working/m-p/79664#M16361</guid>
      <dc:creator>entmgmt</dc:creator>
      <dc:date>2012-11-30T22:14:47Z</dc:date>
    </item>
  </channel>
</rss>

