<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179397#M35988</link>
    <description>&lt;P&gt;Could you try adding the following to the udp://514 stanza:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=syslog
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should work as I have more than a dozen customer installs where the sourcetype is set as syslog, and add-ons such as Cisco ASA add-on and Cisco Networks add-on change the sourcetype based on a transform. This works out of the box with a lot of apps.&lt;/P&gt;

&lt;P&gt;Make sure you do not set a value for the &lt;EM&gt;source&lt;/EM&gt; field, only &lt;EM&gt;sourcetype&lt;/EM&gt;.&lt;/P&gt;</description>
    <pubDate>Fri, 20 Mar 2015 02:40:39 GMT</pubDate>
    <dc:creator>mikaelbje</dc:creator>
    <dc:date>2015-03-20T02:40:39Z</dc:date>
    <item>
      <title>How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179386#M35977</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I have been having issues with getting logs into splunk from our cisco fwsm.  When I open up wireshark I can see network traffic coming in but it does not hit any index.  To prove this theory I searched all of the potential indexes plus looked up via IP address.  I am not sure where to start to troubleshoot.  Does anyone know about debug logs that I can review? I have installed and configured the app as per guidelines written by cisco so I am pretty sure that is ok.  Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2015 00:09:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179386#M35977</guid>
      <dc:creator>domenico_perre</dc:creator>
      <dc:date>2015-03-18T00:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179387#M35978</link>
      <description>&lt;P&gt;Also I have added the following as a catchall just in case and it is still not working.  I have specified both main and ciscocore as the index and no luck.&lt;/P&gt;

&lt;P&gt;Path Splunk\etc\system\local&lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
[host::x.x.x.x]&lt;BR /&gt;
TRANSFORMS-index=sendFirewallLogs&lt;/P&gt;

&lt;P&gt;[host::x.x.x.x]&lt;BR /&gt;
TRANSFORMS-index=sendFirewallLogs2&lt;/P&gt;

&lt;P&gt;[sendFirewallLogs]&lt;BR /&gt;
REGEX=.&lt;BR /&gt;
DEST_KEY=_MetaData:Index&lt;BR /&gt;
FORMAT=main&lt;BR /&gt;
WRITE_META=true&lt;/P&gt;

&lt;P&gt;[sendFirewallLogs2]&lt;BR /&gt;
REGEX=.&lt;BR /&gt;
DEST_KEY=_MetaData:Index&lt;BR /&gt;
FORMAT=main&lt;BR /&gt;
WRITE_META=true&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:10:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179387#M35978</guid>
      <dc:creator>domenico_perre</dc:creator>
      <dc:date>2020-09-28T19:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179388#M35979</link>
      <description>&lt;P&gt;Could you paste the contents of your inputs.conf? You should have a stanza for UDP port 514 or any other port you chose.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2015 06:56:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179388#M35979</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2015-03-18T06:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179389#M35980</link>
      <description>&lt;P&gt;My inputs.conf is in a default state.  &lt;/P&gt;

&lt;P&gt;I can confirm that there is a setting in data inputs and receiving for port 514 and a netstat -ano | findstr "514" shows the UDP port.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 00:49:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179389#M35980</guid>
      <dc:creator>domenico_perre</dc:creator>
      <dc:date>2015-03-19T00:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179390#M35981</link>
      <description>&lt;P&gt;And no data for FWSM when you search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Over all time? All time because we want to rule out any timestamp issues.&lt;/P&gt;

&lt;P&gt;Just a wild guess, but could it be the windows firewall?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 02:22:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179390#M35981</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2015-03-19T02:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179391#M35982</link>
      <description>&lt;P&gt;Nah its cisco fwsm.  Yeah I tried the index=* and there was nothing in the logs.  So for a little more background it was working previously but then stopped one day.  I am not sure why though.  So historic data is still available but not current data.&lt;/P&gt;

&lt;P&gt;Thanks for your help.  Splunk answers was my last ditch effort as I have gone through most of the articles on splunk answers but with no luck :(.&lt;/P&gt;

&lt;P&gt;The old bucket it was going to was 'main'&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 03:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179391#M35982</guid>
      <dc:creator>domenico_perre</dc:creator>
      <dc:date>2015-03-19T03:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179392#M35983</link>
      <description>&lt;P&gt;What I meant was if it could be the Windows firewall blocking inbound connections on UDP port 514, or perhaps another local firewall?&lt;/P&gt;

&lt;P&gt;I assume the traffic you saw in your wireshark capture was coming in on UDP 514? 100% sure no one changed it to TCP on the FWSM?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 06:07:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179392#M35983</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2015-03-19T06:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179393#M35984</link>
      <description>&lt;P&gt;Yeah 100% its on UDP and firewall is not interfering :).  As there is other syslog data coming in on the same port.  Is there any debug logs that I can enable to see why an index is not receiving data?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 06:11:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179393#M35984</guid>
      <dc:creator>domenico_perre</dc:creator>
      <dc:date>2015-03-19T06:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179394#M35985</link>
      <description>&lt;P&gt;Not too sure about what log this would go in, but splunkd.log and splunkd_stdout.log and splunkd_stderr.log would be my guesses.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:15:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179394#M35985</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2020-09-28T19:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179395#M35986</link>
      <description>&lt;P&gt;So I started splunk in debug mode and noticed the following event with the correct source IP of my firewall.  So it seems that the data is being accepted but not sure where though.&lt;/P&gt;

&lt;P&gt;03-20-2015 08:34:30.821 DEBUG UDPInputProcessor - event=data from=x.x.x.x status=accepted&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 22:24:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179395#M35986</guid>
      <dc:creator>domenico_perre</dc:creator>
      <dc:date>2015-03-19T22:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179396#M35987</link>
      <description>&lt;P&gt;So I am going to answer my own question which is a good thing I guess.  The way I understand the issue was the following:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;In Settings | Data Inputs | UDP | 514 the sourcetype was forced to syslog.&lt;/LI&gt;
&lt;LI&gt;The transforms that are part of the cisco ASA /fwsm app install state that the source type is a cisco fwsm.&lt;/LI&gt;
&lt;LI&gt;I had previous data in the main index that was specified as sourcetype cisco:fwsm&lt;/LI&gt;
&lt;LI&gt;The two transforms, 'syslog' (that is forced on the Data inputs) and 'cisco:fwsm' (that is forced from the cisco app) were competing against each other and thus the firewall event was dropped.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;How did I resolve this.  I removed the source 514 from the GUI.&lt;BR /&gt;
In inputs.conf I added the following lines.&lt;/P&gt;

&lt;P&gt;[udp://514]&lt;BR /&gt;
connection_host = ip&lt;/P&gt;

&lt;P&gt;Restarted splunk and it started working.  So the issue which did not rear its ugly head in any debug logs was because of competing transforms I believe.  That moment when you hit the Splunk matrix and everything just works!!!&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2015 00:08:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179396#M35987</guid>
      <dc:creator>domenico_perre</dc:creator>
      <dc:date>2015-03-20T00:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179397#M35988</link>
      <description>&lt;P&gt;Could you try adding the following to the udp://514 stanza:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=syslog
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should work as I have more than a dozen customer installs where the sourcetype is set as syslog, and add-ons such as Cisco ASA add-on and Cisco Networks add-on change the sourcetype based on a transform. This works out of the box with a lot of apps.&lt;/P&gt;

&lt;P&gt;Make sure you do not set a value for the &lt;EM&gt;source&lt;/EM&gt; field, only &lt;EM&gt;sourcetype&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2015 02:40:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179397#M35988</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2015-03-20T02:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179398#M35989</link>
      <description>&lt;P&gt;As soon as I put that field in under the stanza and restarted the splunk service, logs stopped working. &lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2015 03:02:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179398#M35989</guid>
      <dc:creator>domenico_perre</dc:creator>
      <dc:date>2015-03-20T03:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I can see network traffic, but no data is being indexed in Splunk from our Cisco FWSM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179399#M35990</link>
      <description>&lt;P&gt;Could you paste the output of the following commands?&lt;/P&gt;

&lt;P&gt;Go to your Splunk working dir/bin&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk cmd btool props list syslog --debug
./splunk cmd btool inputs list --debug
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 20 Mar 2015 05:41:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-can-see-network-traffic-but-no-data-is/m-p/179399#M35990</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2015-03-20T05:41:39Z</dc:date>
    </item>
  </channel>
</rss>

