<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Not able to see the syslogs of ASA on Splunk Web in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-the-syslogs-of-ASA-on-Splunk-Web/m-p/356067#M65033</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I've configured my ASA to send syslog to splunk server installed on centos. I took capture on ASA and I can see packets are leaving the ASA. I took capture on centOS on port 514 and packets are making to the centOS machine as well. For some reason I don't see them on splunk web.&lt;/P&gt;

&lt;P&gt;I've created data input for UDP port 514 (all default), Source type (cisco:asa). &lt;/P&gt;

&lt;P&gt;I'm really not sure what is the piece of info or config I'm missing here. &lt;/P&gt;

&lt;P&gt;I would appreciate your quick help here.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Dv&lt;/P&gt;</description>
    <pubDate>Wed, 08 Nov 2017 18:05:07 GMT</pubDate>
    <dc:creator>dineshverma</dc:creator>
    <dc:date>2017-11-08T18:05:07Z</dc:date>
    <item>
      <title>Not able to see the syslogs of ASA on Splunk Web</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-the-syslogs-of-ASA-on-Splunk-Web/m-p/356067#M65033</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I've configured my ASA to send syslog to splunk server installed on centos. I took capture on ASA and I can see packets are leaving the ASA. I took capture on centOS on port 514 and packets are making to the centOS machine as well. For some reason I don't see them on splunk web.&lt;/P&gt;

&lt;P&gt;I've created data input for UDP port 514 (all default), Source type (cisco:asa). &lt;/P&gt;

&lt;P&gt;I'm really not sure what is the piece of info or config I'm missing here. &lt;/P&gt;

&lt;P&gt;I would appreciate your quick help here.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Dv&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 18:05:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-the-syslogs-of-ASA-on-Splunk-Web/m-p/356067#M65033</guid>
      <dc:creator>dineshverma</dc:creator>
      <dc:date>2017-11-08T18:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to see the syslogs of ASA on Splunk Web</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-the-syslogs-of-ASA-on-Splunk-Web/m-p/356068#M65034</link>
      <description>&lt;P&gt;What are you using to capture the syslog packets on the linux box?  syslogd, rsyslog, syslog-ng, or splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 20:01:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-the-syslogs-of-ASA-on-Splunk-Web/m-p/356068#M65034</guid>
      <dc:creator>xavierashe</dc:creator>
      <dc:date>2017-11-08T20:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to see the syslogs of ASA on Splunk Web</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-the-syslogs-of-ASA-on-Splunk-Web/m-p/356069#M65035</link>
      <description>&lt;P&gt;Are you looking to get data from your firewall for security events? If this is the case, you will need to install the Splunk for Cisco Security App which will provide a dashboard that contains Security Event Statistics, as well as being able to look at a Firewall Overview or Event Search.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 20:44:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-the-syslogs-of-ASA-on-Splunk-Web/m-p/356069#M65035</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2017-11-08T20:44:06Z</dc:date>
    </item>
  </channel>
</rss>

