<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA Addon - No Event Types in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-ASA-Addon-No-Event-Types/m-p/39538#M7355</link>
    <description>&lt;P&gt;This time I tried the Cisco for Firewalls App and the Cisco Security Suite app.&lt;/P&gt;

&lt;P&gt;STILL no events showing even thought it is definitely logging:&lt;/P&gt;

&lt;P&gt;This search has completed and found 7,504 matching events. However, the transforming commands in the highlighted portion of the following search:&lt;/P&gt;

&lt;P&gt;search eventtype="cisco_firewall" | bin _time span=5m | search eventtype="cisco_firewall" | &lt;STRONG&gt;stats count by eventtype, src_ip, dest_ip, host,log_level_desc,event_desc, _time&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;over the time range: 8/20/12 5:27:16.000 PM – 8/21/12 5:27:16.000 AM&lt;BR /&gt;
generated no results. &lt;/P&gt;

&lt;P&gt;Again lots of raw events in the log with the correct source_type:&lt;/P&gt;

&lt;P&gt;5:29:44.000 AM  Aug 21 05:29:44 10.11.121.2 %ASA-6-302020: Built outbound ICMP connection for faddr x.x.81.124/0 gaddr x.x.247.193/28571 laddr 10.1.5.62/28571host=splunk   Options|  sourcetype=udp:514   Options|  source=udp:514   Options &lt;BR /&gt;
2 » 8/21/12&lt;BR /&gt;
5:29:44.000 AM  Aug 21 05:29:44 10.11.121.2 %ASA-6-305011: Built dynamic ICMP translation from any:10.1.5.62/28571 to outside:x.x.247.193/28571host=splunk   Options|  sourcetype=udp:514   Options|  source=udp:514   Options &lt;BR /&gt;
3 » 8/21/12&lt;BR /&gt;
5:29:44.000 AM  Aug 21 05:29:44 10.11.121.2 %ASA-6-305012: Teardown dynamic UDP translation from any:10.1.1.65/50482 to outside:x.x.247.193/50482 duration 0:00:30host=splunk   Options|  sourcetype=udp:514   Options|  source=udp:514   Options &lt;BR /&gt;
4 » 8/21/12&lt;BR /&gt;
5:29:44.000 AM  Aug 21 05:29:44 10.11.121.2 %ASA-6-305012: Teardown dynamic ICMP translation from any:10.1.5.62/61987 to outside:x.x.247.193/61987 duration 0:00:32 &lt;/P&gt;

&lt;P&gt;Splunk: 4.3.3 b128297&lt;BR /&gt;
ASA: 8.4(4)&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 12:18:03 GMT</pubDate>
    <dc:creator>quesse2</dc:creator>
    <dc:date>2020-09-28T12:18:03Z</dc:date>
    <item>
      <title>Cisco ASA Addon - No Event Types</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-ASA-Addon-No-Event-Types/m-p/39537#M7354</link>
      <description>&lt;P&gt;The add-on is installed correctly and functioning.&lt;/P&gt;

&lt;P&gt;Data Input is defined as:&lt;/P&gt;

&lt;P&gt;UDP/514, Source Type: cisco_asa, Index: firewall&lt;/P&gt;

&lt;P&gt;I'm getting data, events # increments in the Cisco Splunk App, but Event Types is empty.&lt;/P&gt;

&lt;P&gt;Syslog on the ASA is setup to do Informational.&lt;/P&gt;

&lt;P&gt;Raw events in Splunk look like:&lt;/P&gt;

&lt;P&gt;8/20/12 9:13:33.000 AM  Aug 20 09:13:33 10.11.121.2 %ASA-4-106023: Deny udp src inside:10.1.5.219/54057 dst outside:X.X.127.74/8102 by access-group "inside_access_in" [0x0, 0x0]host=10.11.121.2   Options|  sourcetype=syslog   Options|  source=udp:514   Options &lt;/P&gt;

&lt;P&gt;Source Type column under Data Inputs is confirmed as 'cisco_asa', sourcetype in log itself says 'syslog' not sure if that has anything to do with it.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:17:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-ASA-Addon-No-Event-Types/m-p/39537#M7354</guid>
      <dc:creator>quesse2</dc:creator>
      <dc:date>2020-09-28T12:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Addon - No Event Types</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-ASA-Addon-No-Event-Types/m-p/39538#M7355</link>
      <description>&lt;P&gt;This time I tried the Cisco for Firewalls App and the Cisco Security Suite app.&lt;/P&gt;

&lt;P&gt;STILL no events showing even thought it is definitely logging:&lt;/P&gt;

&lt;P&gt;This search has completed and found 7,504 matching events. However, the transforming commands in the highlighted portion of the following search:&lt;/P&gt;

&lt;P&gt;search eventtype="cisco_firewall" | bin _time span=5m | search eventtype="cisco_firewall" | &lt;STRONG&gt;stats count by eventtype, src_ip, dest_ip, host,log_level_desc,event_desc, _time&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;over the time range: 8/20/12 5:27:16.000 PM – 8/21/12 5:27:16.000 AM&lt;BR /&gt;
generated no results. &lt;/P&gt;

&lt;P&gt;Again lots of raw events in the log with the correct source_type:&lt;/P&gt;

&lt;P&gt;5:29:44.000 AM  Aug 21 05:29:44 10.11.121.2 %ASA-6-302020: Built outbound ICMP connection for faddr x.x.81.124/0 gaddr x.x.247.193/28571 laddr 10.1.5.62/28571host=splunk   Options|  sourcetype=udp:514   Options|  source=udp:514   Options &lt;BR /&gt;
2 » 8/21/12&lt;BR /&gt;
5:29:44.000 AM  Aug 21 05:29:44 10.11.121.2 %ASA-6-305011: Built dynamic ICMP translation from any:10.1.5.62/28571 to outside:x.x.247.193/28571host=splunk   Options|  sourcetype=udp:514   Options|  source=udp:514   Options &lt;BR /&gt;
3 » 8/21/12&lt;BR /&gt;
5:29:44.000 AM  Aug 21 05:29:44 10.11.121.2 %ASA-6-305012: Teardown dynamic UDP translation from any:10.1.1.65/50482 to outside:x.x.247.193/50482 duration 0:00:30host=splunk   Options|  sourcetype=udp:514   Options|  source=udp:514   Options &lt;BR /&gt;
4 » 8/21/12&lt;BR /&gt;
5:29:44.000 AM  Aug 21 05:29:44 10.11.121.2 %ASA-6-305012: Teardown dynamic ICMP translation from any:10.1.5.62/61987 to outside:x.x.247.193/61987 duration 0:00:32 &lt;/P&gt;

&lt;P&gt;Splunk: 4.3.3 b128297&lt;BR /&gt;
ASA: 8.4(4)&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:18:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-ASA-Addon-No-Event-Types/m-p/39538#M7355</guid>
      <dc:creator>quesse2</dc:creator>
      <dc:date>2020-09-28T12:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Addon - No Event Types</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-ASA-Addon-No-Event-Types/m-p/39539#M7356</link>
      <description>&lt;P&gt;Looks like your fields are not getting extracted properly. When you do just a regular 'raw' search, do you see fields like eventtype, src_ip, dest_ip etc being populated?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:18:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-ASA-Addon-No-Event-Types/m-p/39539#M7356</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2020-09-28T12:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Addon - No Event Types</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-ASA-Addon-No-Event-Types/m-p/39540#M7357</link>
      <description>&lt;P&gt;Definitely agree that fields are not getting extracted. But I just don't know how to figure out why? I have a brand new ASA so I'm wondering if there wasn't a change in the output?&lt;/P&gt;

&lt;P&gt;That's why I included the raw output so maybe someone could compare to an older ASA version. Where would I go to see 'eventtype'/xxx_ip being populated? &lt;/P&gt;

&lt;P&gt;In the Cisco Security App, I do a "search Cisco Firewall Recent Events" and it says 'eventtype=cisco_firewall' and then gives me 1000's of raw events. But the dashboard shows nothing - the events aren't being interpreted correctly.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2012 13:41:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-ASA-Addon-No-Event-Types/m-p/39540#M7357</guid>
      <dc:creator>quesse2</dc:creator>
      <dc:date>2012-08-21T13:41:26Z</dc:date>
    </item>
  </channel>
</rss>

