<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using Splunk to help define required Cisco ASA rules in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-to-help-define-required-Cisco-ASA-rules/m-p/341858#M62981</link>
    <description>&lt;P&gt;Hello folks,&lt;/P&gt;

&lt;P&gt;Is Splunk able to help me generate rules to put on an ASA?&lt;/P&gt;

&lt;P&gt;We're running an ASA in transparent mode with a single allow rule, logging all traffic seen through to Splunk.  The plan is to take that data generated and build the ruleset for the firewall based on a ratified version of the data.  I was thinking of first running a report that does a summary of all destination addresses, sorted by number of occurrences, and then for each of the results, a further report to show me the ports that were connected to on those IP's.  Which I can see working just fine.&lt;/P&gt;

&lt;P&gt;So, my question really is: Is there a slicker and quicker way of generating this data?  I've toyed with writing a Python script to chew through the logs, but I'd rather have it all centralised in Splunk.&lt;/P&gt;

&lt;P&gt;Any guidance will be gratefully received.&lt;/P&gt;

&lt;P&gt;Best, Leigh&lt;/P&gt;</description>
    <pubDate>Thu, 02 Nov 2017 13:33:08 GMT</pubDate>
    <dc:creator>gestaltnetworks</dc:creator>
    <dc:date>2017-11-02T13:33:08Z</dc:date>
    <item>
      <title>Using Splunk to help define required Cisco ASA rules</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-to-help-define-required-Cisco-ASA-rules/m-p/341858#M62981</link>
      <description>&lt;P&gt;Hello folks,&lt;/P&gt;

&lt;P&gt;Is Splunk able to help me generate rules to put on an ASA?&lt;/P&gt;

&lt;P&gt;We're running an ASA in transparent mode with a single allow rule, logging all traffic seen through to Splunk.  The plan is to take that data generated and build the ruleset for the firewall based on a ratified version of the data.  I was thinking of first running a report that does a summary of all destination addresses, sorted by number of occurrences, and then for each of the results, a further report to show me the ports that were connected to on those IP's.  Which I can see working just fine.&lt;/P&gt;

&lt;P&gt;So, my question really is: Is there a slicker and quicker way of generating this data?  I've toyed with writing a Python script to chew through the logs, but I'd rather have it all centralised in Splunk.&lt;/P&gt;

&lt;P&gt;Any guidance will be gratefully received.&lt;/P&gt;

&lt;P&gt;Best, Leigh&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 13:33:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-to-help-define-required-Cisco-ASA-rules/m-p/341858#M62981</guid>
      <dc:creator>gestaltnetworks</dc:creator>
      <dc:date>2017-11-02T13:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk to help define required Cisco ASA rules</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-to-help-define-required-Cisco-ASA-rules/m-p/341859#M62982</link>
      <description>&lt;P&gt;Hi Leigh, &lt;/P&gt;

&lt;P&gt;It sounds like you would be heavily interested in the splunk add on for cisco asa. I think  it can get you pretty far as what you are interested in. I included the link below from splunkbase. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/1620/"&gt;https://splunkbase.splunk.com/app/1620/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 18:33:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-to-help-define-required-Cisco-ASA-rules/m-p/341859#M62982</guid>
      <dc:creator>NuHarborMatt</dc:creator>
      <dc:date>2017-11-03T18:33:52Z</dc:date>
    </item>
  </channel>
</rss>

