<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Security Suite and Cisco Firewall Add-on Installation in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Security-Suite-and-Cisco-Firewall-Add-on-Installation/m-p/101953#M21386</link>
    <description>&lt;P&gt;Hi I have the same issue and my sourcetype is cisco::asa??&lt;/P&gt;</description>
    <pubDate>Wed, 08 May 2013 11:48:46 GMT</pubDate>
    <dc:creator>dapatter75</dc:creator>
    <dc:date>2013-05-08T11:48:46Z</dc:date>
    <item>
      <title>Cisco Security Suite and Cisco Firewall Add-on Installation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Security-Suite-and-Cisco-Firewall-Add-on-Installation/m-p/101950#M21383</link>
      <description>&lt;P&gt;I have installed both Cisco Security Suite and Cisco Firewall Add-On, I have UDP 514 port excepting log data from a Syslogs server.  I can view realtime data in the Cisco Firewall app, but no results in the Cisco Security Suite.  Is there something I'm missing?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 16:28:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Security-Suite-and-Cisco-Firewall-Add-on-Installation/m-p/101950#M21383</guid>
      <dc:creator>jocogov</dc:creator>
      <dc:date>2013-01-28T16:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite and Cisco Firewall Add-on Installation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Security-Suite-and-Cisco-Firewall-Add-on-Installation/m-p/101951#M21384</link>
      <description>&lt;P&gt;I get the same thing here, it worked before the update.  I hope some one fixes this.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2013 16:35:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Security-Suite-and-Cisco-Firewall-Add-on-Installation/m-p/101951#M21384</guid>
      <dc:creator>idsersupport</dc:creator>
      <dc:date>2013-01-30T16:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite and Cisco Firewall Add-on Installation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Security-Suite-and-Cisco-Firewall-Add-on-Installation/m-p/101952#M21385</link>
      <description>&lt;P&gt;After running into the same issue, the sourcetype renaming is probably not occurring because the regular expression used to force the sourcetype was changed from the previous version of the Splunk for Firewall app.  Below shows what the previous version had specified in the transforms.conf, and what it was changed to.&lt;BR /&gt;&lt;BR /&gt;
It was updated &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;FROM:&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;[force_sourcetype_for_cisco_asa]&lt;BR /&gt;&lt;BR /&gt;
DEST_KEY = MetaData:Sourcetype&lt;BR /&gt;&lt;BR /&gt;
REGEX = %ASA-\d+-\d+&lt;BR /&gt;&lt;BR /&gt;
FORMAT = sourcetype::cisco_asa  &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;TO:&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;[force_sourcetype_for_cisco_asa]&lt;BR /&gt;&lt;BR /&gt;
DEST_KEY = MetaData:Sourcetype&lt;BR /&gt;&lt;BR /&gt;
#REGEX = %ASA-\d+-\d+&lt;BR /&gt;&lt;BR /&gt;
REGEX = %ASA--\d+-\d+&lt;BR /&gt;&lt;BR /&gt;
FORMAT = sourcetype::cisco_asa&lt;BR /&gt;&lt;BR /&gt;
Note the extra - in the Regex.&lt;BR /&gt;&lt;BR /&gt;
So to change this, just create a transforms.conf in $SPLUNK_HOME/etc/apps/Splunk_CiscoFirewalls/local, if not already there, and update the REGEX string.   &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:36:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Security-Suite-and-Cisco-Firewall-Add-on-Installation/m-p/101952#M21385</guid>
      <dc:creator>shogan_splunk</dc:creator>
      <dc:date>2020-09-28T13:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite and Cisco Firewall Add-on Installation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Security-Suite-and-Cisco-Firewall-Add-on-Installation/m-p/101953#M21386</link>
      <description>&lt;P&gt;Hi I have the same issue and my sourcetype is cisco::asa??&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2013 11:48:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Security-Suite-and-Cisco-Firewall-Add-on-Installation/m-p/101953#M21386</guid>
      <dc:creator>dapatter75</dc:creator>
      <dc:date>2013-05-08T11:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Security Suite and Cisco Firewall Add-on Installation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Security-Suite-and-Cisco-Firewall-Add-on-Installation/m-p/101954#M21387</link>
      <description>&lt;P&gt;I am also in the same predicament that the Cisco Security Overview does not display Global Security Events, Top Threats, Top Sources, Top Destinations, Top Services, Security Event Statistics by Sourcetype and Security Event Statistics by Host&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 11:44:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Security-Suite-and-Cisco-Firewall-Add-on-Installation/m-p/101954#M21387</guid>
      <dc:creator>f10353</dc:creator>
      <dc:date>2016-09-14T11:44:08Z</dc:date>
    </item>
  </channel>
</rss>

