<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to get data from ASA in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-from-ASA/m-p/299006#M93036</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am on an ASA 9.1 release, splunk 6.5.2, Splunk _TA_cisco-asa 3.2.6&lt;/P&gt;

&lt;P&gt;I have configured the ASA syslog to send data to Splunk on port 5555.&lt;/P&gt;

&lt;P&gt;listening on port 5555 on splunk receiving.&lt;/P&gt;

&lt;P&gt;Please let me know what I am missing. Hopefully not too much of a newbie question:)&lt;BR /&gt;
thanks&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 13:26:16 GMT</pubDate>
    <dc:creator>rgraham29975</dc:creator>
    <dc:date>2020-09-29T13:26:16Z</dc:date>
    <item>
      <title>Unable to get data from ASA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-from-ASA/m-p/299006#M93036</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am on an ASA 9.1 release, splunk 6.5.2, Splunk _TA_cisco-asa 3.2.6&lt;/P&gt;

&lt;P&gt;I have configured the ASA syslog to send data to Splunk on port 5555.&lt;/P&gt;

&lt;P&gt;listening on port 5555 on splunk receiving.&lt;/P&gt;

&lt;P&gt;Please let me know what I am missing. Hopefully not too much of a newbie question:)&lt;BR /&gt;
thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-from-ASA/m-p/299006#M93036</guid>
      <dc:creator>rgraham29975</dc:creator>
      <dc:date>2020-09-29T13:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get data from ASA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-from-ASA/m-p/299007#M93037</link>
      <description>&lt;P&gt;Are the ASA and Splunk using the same protocol (TCP vs. UDP)?&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 12:46:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-from-ASA/m-p/299007#M93037</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-03-31T12:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get data from ASA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-from-ASA/m-p/299008#M93038</link>
      <description>&lt;P&gt;Dumb question:  Are the ports open if there is a firewall?&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 13:23:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-from-ASA/m-p/299008#M93038</guid>
      <dc:creator>atari1050</dc:creator>
      <dc:date>2017-03-31T13:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get data from ASA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-from-ASA/m-p/299009#M93039</link>
      <description>&lt;P&gt;This default app is configured for port 514 in the props.conf file in the add-on/default folder.  To fix it, if you are new, just create a folder/directory called local in the add-on directory and add a new &lt;STRONG&gt;props.conf&lt;/STRONG&gt; with the following information.  A local props.conf with the stanzas below overrides the ones in default per the order of precedence in Splunk.  Do not alter the default/props.conf file.&lt;/P&gt;

&lt;P&gt;Directory Path:  $SPLUNK_HOME/etc/apps/Splunk_TA_cisco-asa/local/props.conf&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;[source::tcp:5555]&lt;BR /&gt;
TRANSFORMS-force_sourcetype_for_cisco = force_sourcetype_for_cisco_asa,force_sourcetype_for_cisco_pix,force_sourcetype_for_cisco_fwsm&lt;/P&gt;

&lt;P&gt;[source::udp:5555]&lt;BR /&gt;
TRANSFORMS-force_sourcetype_for_cisco = force_sourcetype_for_cisco_asa,force_sourcetype_for_cisco_pix,force_sourcetype_for_cisco_fwsm&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-from-ASA/m-p/299009#M93039</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2020-09-29T13:26:27Z</dc:date>
    </item>
  </channel>
</rss>

