<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filtering Cisco ASA Session log to remove logging for a session ID and IP combination in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-Cisco-ASA-Session-log-to-remove-logging-for-a-session/m-p/529317#M89180</link>
    <description>&lt;P&gt;Hi, I meant I want to keep ID&lt;SPAN&gt;302013. But I don't&amp;nbsp;want to keep&amp;nbsp; ID302013 if it contains a specific IP address.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I wanted to try and simplify the set up rather than have multiple&amp;nbsp;servers, we don't&amp;nbsp;have much resource here, but may have to look and see if there a syslog server that may make the filtering bit a bit easier. The way to filter in Splunk doesn't&amp;nbsp;look the easiest to implement, which is why I&amp;nbsp;did as much as I could from the source device.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Nov 2020 15:12:23 GMT</pubDate>
    <dc:creator>timoggy</dc:creator>
    <dc:date>2020-11-13T15:12:23Z</dc:date>
    <item>
      <title>Filtering Cisco ASA Session log to remove logging for a session ID and IP combination</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-Cisco-ASA-Session-log-to-remove-logging-for-a-session/m-p/529286#M89175</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm very new to Splunk,&amp;nbsp; and struggling to find a way to filter a specific log which is consuming a large proportion of my license.&lt;/P&gt;&lt;P&gt;I have a Cisco ASA set up to send events to Splunk UDP port as syslog. I've restricted the logs to what I want to see by using the Built in filter tools within the ASA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what I can see within the forum, there are lots of people asking how to filter based off Syslog ID, but I want to filter out based off Syslog ID 302013 and IP xxx.xxx.xxx.xxx, as I want to keep 302013 apart from anything containing that specific IP.&lt;/P&gt;&lt;P&gt;I don't even know where to start, but I know this can't be done from the cisco device, so has to be done on the Splunk server.&lt;/P&gt;&lt;P&gt;Would really appreciate someone pointing me in the right direction.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 11:30:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-Cisco-ASA-Session-log-to-remove-logging-for-a-session/m-p/529286#M89175</guid>
      <dc:creator>timoggy</dc:creator>
      <dc:date>2020-11-13T11:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering Cisco ASA Session log to remove logging for a session ID and IP combination</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-Cisco-ASA-Session-log-to-remove-logging-for-a-session/m-p/529312#M89178</link>
      <description>&lt;P&gt;Please clarify your requirements since "filter" and "keep apart" mean two different things in my world.&amp;nbsp; What do you want to do with the ID 302013 events?&lt;/P&gt;&lt;P&gt;Have read the docs on filtering events?&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Routeandfilterdatad" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Are you aware that sending syslog directly to Splunk is discouraged?&amp;nbsp; Best Practice is to send syslog to a dedicated syslog server and then forward to Splunk.&amp;nbsp; This helps to reduce data loss, plus syslog server often have built-in filtering features.&amp;nbsp; See&amp;nbsp;&lt;A href="http://www.georgestarcher.com/splunk-success-with-syslog/" target="_blank"&gt;http://www.georgestarcher.com/splunk-success-with-syslog/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 14:43:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-Cisco-ASA-Session-log-to-remove-logging-for-a-session/m-p/529312#M89178</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-13T14:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering Cisco ASA Session log to remove logging for a session ID and IP combination</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-Cisco-ASA-Session-log-to-remove-logging-for-a-session/m-p/529317#M89180</link>
      <description>&lt;P&gt;Hi, I meant I want to keep ID&lt;SPAN&gt;302013. But I don't&amp;nbsp;want to keep&amp;nbsp; ID302013 if it contains a specific IP address.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I wanted to try and simplify the set up rather than have multiple&amp;nbsp;servers, we don't&amp;nbsp;have much resource here, but may have to look and see if there a syslog server that may make the filtering bit a bit easier. The way to filter in Splunk doesn't&amp;nbsp;look the easiest to implement, which is why I&amp;nbsp;did as much as I could from the source device.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 15:12:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-Cisco-ASA-Session-log-to-remove-logging-for-a-session/m-p/529317#M89180</guid>
      <dc:creator>timoggy</dc:creator>
      <dc:date>2020-11-13T15:12:23Z</dc:date>
    </item>
  </channel>
</rss>

