<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco logs though Heavy Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-logs-though-Heavy-Forwarder/m-p/529445#M89190</link>
    <description>Hi&lt;BR /&gt;Here is example how filter ASA logs &lt;A href="https://community.splunk.com/t5/Getting-Data-In/Trying-to-filter-ASA-syslogs-before-indexing-to-avoid-license/m-p/283476" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Trying-to-filter-ASA-syslogs-before-indexing-to-avoid-license/m-p/283476&lt;/A&gt;&lt;BR /&gt;You must update it based on what you want exactly filter out.&lt;BR /&gt;And you must do those filtering on HF not Indexers.&lt;BR /&gt;r. Ismo</description>
    <pubDate>Sun, 15 Nov 2020 10:17:48 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-11-15T10:17:48Z</dc:date>
    <item>
      <title>Cisco logs though Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-logs-though-Heavy-Forwarder/m-p/529423#M89188</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I'm trying to collect logs from Cisco ASA devices through Heavy Forwarder, I'm sending all Cisco ASA logs to my HF instance and then send them to indexers.&lt;/P&gt;&lt;P&gt;I want to parse these logs and send to indexers only VPN-event logs. How can I filter them?&lt;/P&gt;&lt;P&gt;Can I filter them using event types from Cisco Add-on?&lt;/P&gt;</description>
      <pubDate>Sat, 14 Nov 2020 21:28:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-logs-though-Heavy-Forwarder/m-p/529423#M89188</guid>
      <dc:creator>tmardan</dc:creator>
      <dc:date>2020-11-14T21:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco logs though Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-logs-though-Heavy-Forwarder/m-p/529445#M89190</link>
      <description>Hi&lt;BR /&gt;Here is example how filter ASA logs &lt;A href="https://community.splunk.com/t5/Getting-Data-In/Trying-to-filter-ASA-syslogs-before-indexing-to-avoid-license/m-p/283476" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Trying-to-filter-ASA-syslogs-before-indexing-to-avoid-license/m-p/283476&lt;/A&gt;&lt;BR /&gt;You must update it based on what you want exactly filter out.&lt;BR /&gt;And you must do those filtering on HF not Indexers.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Sun, 15 Nov 2020 10:17:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-logs-though-Heavy-Forwarder/m-p/529445#M89190</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-11-15T10:17:48Z</dc:date>
    </item>
  </channel>
</rss>

