<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Anyconnect via Syslog in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Anyconnect-via-Syslog/m-p/461616#M79652</link>
    <description>&lt;P&gt;You have to install the &lt;CODE&gt;Splunk Add-on for Cisco ASA&lt;/CODE&gt;:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/1620/"&gt;https://splunkbase.splunk.com/app/1620/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Mar 2020 23:36:37 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2020-03-30T23:36:37Z</dc:date>
    <item>
      <title>Cisco Anyconnect via Syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Anyconnect-via-Syslog/m-p/461615#M79651</link>
      <description>&lt;P&gt;Greetings.  This may be elementary, but I have our Cisco ASA 5516 sending logs via a syslog server to Splunk.  I configured a basic inputs.conf file to do so.&lt;/P&gt;

&lt;P&gt;The logs get into Splunk but the parsing isn't very good.  I seem to have to extract most fields (like I saw in another question re: message_id field.)  Shouldn't those fields be parsed automatically?  I don't see an AnyConnect TA or app except for NVM which my infrastructure team says we're not using.&lt;/P&gt;

&lt;P&gt;Any guidance would be much appreciated.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 21:43:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Anyconnect-via-Syslog/m-p/461615#M79651</guid>
      <dc:creator>sbgoldberg13</dc:creator>
      <dc:date>2020-03-30T21:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Anyconnect via Syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Anyconnect-via-Syslog/m-p/461616#M79652</link>
      <description>&lt;P&gt;You have to install the &lt;CODE&gt;Splunk Add-on for Cisco ASA&lt;/CODE&gt;:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/1620/"&gt;https://splunkbase.splunk.com/app/1620/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 23:36:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Anyconnect-via-Syslog/m-p/461616#M79652</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-03-30T23:36:37Z</dc:date>
    </item>
  </channel>
</rss>

