<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Changing sourcetype for FWSM in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11208#M531</link>
    <description>&lt;P&gt;All data is received on UDP port 514. The file I changed in firewall_addon was the configuration option under app management in Splunk.&lt;/P&gt;</description>
    <pubDate>Sat, 10 Apr 2010 05:54:51 GMT</pubDate>
    <dc:creator>pillowhead</dc:creator>
    <dc:date>2010-04-10T05:54:51Z</dc:date>
    <item>
      <title>Changing sourcetype for FWSM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11206#M529</link>
      <description>&lt;P&gt;Hi, I just installed cisco_firewall_addon for version 4.1 of splunk and I am having some issues. I have an ASA and a FWSM that I want to be recognized as a cisco_firewall sourcetype. The ASA is correctly recognized, but the FWSM is still categorized as cisco_syslog. I already went into the cisco_firewall_addon app config and changed it from %ASA OR %PIX to %ASA OR %PIX OR %FWSM and restarted, but that didn't resolve the issue. How do I change the FWSM to be recognized as cisco_firewall?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2010 23:23:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11206#M529</guid>
      <dc:creator>pillowhead</dc:creator>
      <dc:date>2010-04-09T23:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Changing sourcetype for FWSM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11207#M530</link>
      <description>&lt;P&gt;0&lt;/P&gt;

&lt;P&gt;How are you receiving the data? All syslog on the same port? What file did you change in the firewall_addon app?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Apr 2010 04:25:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11207#M530</guid>
      <dc:creator>dskillman</dc:creator>
      <dc:date>2010-04-10T04:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Changing sourcetype for FWSM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11208#M531</link>
      <description>&lt;P&gt;All data is received on UDP port 514. The file I changed in firewall_addon was the configuration option under app management in Splunk.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Apr 2010 05:54:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11208#M531</guid>
      <dc:creator>pillowhead</dc:creator>
      <dc:date>2010-04-10T05:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Changing sourcetype for FWSM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11209#M532</link>
      <description>&lt;P&gt;Hello,
We are in the process of updating the Cisco Firewall Add-on to support FWSM but for now there are a couple of steps you can take manually and this should get things working for you.&lt;/P&gt;

&lt;P&gt;in the local directory of the app you need to create a transforms.conf, props.conf and eventtypes.conf file if you have not done so already.&lt;/P&gt;

&lt;P&gt;In transforms add the following stanza: &lt;/P&gt;

&lt;P&gt;[cisco_fwsm]&lt;BR /&gt;
DEST_KEY = MetaData:Sourcetype&lt;BR /&gt;
REGEX = (%FWSM)&lt;BR /&gt;
FORMAT = sourcetype::cisco_firewall&lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;in props.conf add the following to the top of the file:&lt;/P&gt;

&lt;P&gt;TRANSFORMS-pix=cisco_fwsm&lt;/P&gt;

&lt;P&gt;in eventtypes.conf add the following stanza:&lt;/P&gt;

&lt;P&gt;[cisco_firewall]&lt;BR /&gt;
search = %ASA OR %PIX OR %FWSM&lt;BR /&gt;
tags = cisco firewall&lt;/P&gt;

&lt;P&gt;This should be all you need to get the add-on working correctly with your firewall. Please let us know how it works out for you. &lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2010 09:01:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11209#M532</guid>
      <dc:creator>Will_Hayes</dc:creator>
      <dc:date>2010-04-12T09:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: Changing sourcetype for FWSM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11210#M533</link>
      <description>&lt;P&gt;That fixed it. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2010 02:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11210#M533</guid>
      <dc:creator>pillowhead</dc:creator>
      <dc:date>2010-04-13T02:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Changing sourcetype for FWSM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11211#M534</link>
      <description>&lt;P&gt;@pillowhead - since @Will Hayes's answer below answered your question, you should click the checkmark next to his answer so he'll get the reputation points for a good answer (and you'll get 2 points for your trouble). thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2010 03:08:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Changing-sourcetype-for-FWSM/m-p/11211#M534</guid>
      <dc:creator>Justin_Grant</dc:creator>
      <dc:date>2010-04-14T03:08:03Z</dc:date>
    </item>
  </channel>
</rss>

