<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk security suite installation in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189229#M10025</link>
    <description>&lt;P&gt;Is the sourcetype located in the props.conf file within the main app or under the TA/ SA?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Oct 2014 17:31:20 GMT</pubDate>
    <dc:creator>jamesy281</dc:creator>
    <dc:date>2014-10-30T17:31:20Z</dc:date>
    <item>
      <title>Splunk security suite installation</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189224#M10020</link>
      <description>&lt;P&gt;Hey there,&lt;/P&gt;

&lt;P&gt;I need some help with the Cisco Security suite. we are running a distributed environment which consists of 1 X master, 1x serach head and two indexers. The app was installed using the WEB ui by my predecessor along with the SA and TA. Our ASA is directed to one of the indexres via syslog UDP 514 and I can search this fine. The dashboard was showing no data so I followed a ton of KB articles and made changes as suggested I even installed the TA on both indexers however after rebooting I just got a bunch of errors. I ended up just uninstalling all the components completely. my question is what is the correct installation procedure in a distributed environment such as mine? all the documents say install it in $Splunkhome..., etc but not on what servers it is required. Do I simply need to install on the search head and copy the apps to the apps directory and that is it or is it required on the indexers also?&lt;/P&gt;

&lt;P&gt;Any help is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 10:24:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189224#M10020</guid>
      <dc:creator>jamesy281</dc:creator>
      <dc:date>2014-10-30T10:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk security suite installation</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189225#M10021</link>
      <description>&lt;P&gt;You have to install the Suite, your TA's and SA  on the search head. &lt;BR /&gt;
You also have to install your SA's (yust copy that part from your Suite app directory) as separate apps in $SPLUNK-HOME/etc/apps/&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 16:17:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189225#M10021</guid>
      <dc:creator>frmaasdam</dc:creator>
      <dc:date>2014-10-30T16:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk security suite installation</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189226#M10022</link>
      <description>&lt;P&gt;Hi frmassdam,&lt;/P&gt;

&lt;P&gt;Thanks for the reply. This is the original configuration that I had but the dashboard didn't show any data.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 16:38:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189226#M10022</guid>
      <dc:creator>jamesy281</dc:creator>
      <dc:date>2014-10-30T16:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk security suite installation</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189227#M10023</link>
      <description>&lt;P&gt;Another remark. Check your sourcetype! So far I know it has been changed from cisco-asa ? to cisco:asa   &lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 17:01:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189227#M10023</guid>
      <dc:creator>frmaasdam</dc:creator>
      <dc:date>2014-10-30T17:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk security suite installation</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189228#M10024</link>
      <description>&lt;P&gt;Of course you can check within your dashboard the search that has been done and failed. &lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 17:02:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189228#M10024</guid>
      <dc:creator>frmaasdam</dc:creator>
      <dc:date>2014-10-30T17:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk security suite installation</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189229#M10025</link>
      <description>&lt;P&gt;Is the sourcetype located in the props.conf file within the main app or under the TA/ SA?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 17:31:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189229#M10025</guid>
      <dc:creator>jamesy281</dc:creator>
      <dc:date>2014-10-30T17:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk security suite installation</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189230#M10026</link>
      <description>&lt;P&gt;Standard files from your app:&lt;/P&gt;

&lt;P&gt;SA-cisco-asa/default/eventtypes.conf:search = (sourcetype="cisco:asa" OR sourcetype="cisco:pix" OR sourcetype="cisco:fwsm")&lt;/P&gt;

&lt;P&gt;SA-cisco-asa/default/props.conf:[cisco:asa]&lt;/P&gt;

&lt;P&gt;Splunk_CiscoSecuritySuite/lookups/cisco_device_info.csv:cisco:asa,cisco:asa,Firewall,network,Cisco,ASA,Adaptive Security Appliance&lt;/P&gt;

&lt;P&gt;Splunk_TA_cisco-asa/default/eventgen.conf:sourcetype=cisco:asa&lt;/P&gt;

&lt;P&gt;Splunk_TA_cisco-asa/default/eventtypes.conf:search = (sourcetype="cisco:asa" OR sourcetype="cisco:pix") message_id="4000*"&lt;/P&gt;

&lt;P&gt;Splunk_TA_cisco-asa/default/props.conf:sourcetype = cisco:asa&lt;BR /&gt;
Splunk_TA_cisco-asa/default/props.conf:[cisco:asa]&lt;/P&gt;

&lt;P&gt;Splunk_TA_cisco-asa/default/transforms.conf:FORMAT = sourcetype::cisco:asa&lt;/P&gt;

&lt;P&gt;Splunk_TA_cisco-asa/lookups/cisco_asa_ids_lookup.csv:cisco:asa,network&lt;/P&gt;

&lt;P&gt;Our inputfiles from our UFW:&lt;/P&gt;

&lt;P&gt;WG-CINP010_il_netwerk_fwdsyslog/default/inputs.conf:sourcetype = cisco:asa&lt;BR /&gt;
WG-CINP010_il_netwerk_fwdsyslog/default/inputs.conf:sourcetype = cisco:asa&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:02:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189230#M10026</guid>
      <dc:creator>frmaasdam</dc:creator>
      <dc:date>2020-09-28T18:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk security suite installation</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189231#M10027</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;I will install fresh with the most recent version on the search head. I have downloaded the Cisco Security Suite and the splunk add on for ASA, when I extract it it is listed as Splunk_TA_cisco_asa. is there an additional component (SA)? I can't see that on the site.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:02:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189231#M10027</guid>
      <dc:creator>jamesy281</dc:creator>
      <dc:date>2020-09-28T18:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk security suite installation</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189232#M10028</link>
      <description>&lt;P&gt;You can find your SA in Splunk_CiscoSecuritySuite/appserver/addons&lt;BR /&gt;
You have to copy the desired SA directory to $SPLUNK-HOME/etc/apps&lt;BR /&gt;
This will enable the SA asa dashboard in the SecuritySuite dashboard&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 18:37:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189232#M10028</guid>
      <dc:creator>frmaasdam</dc:creator>
      <dc:date>2014-10-30T18:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk security suite installation</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189233#M10029</link>
      <description>&lt;P&gt;Do you share the solution when you have it working again?&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 10:53:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189233#M10029</guid>
      <dc:creator>frmaasdam</dc:creator>
      <dc:date>2014-10-31T10:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk security suite installation</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189234#M10030</link>
      <description>&lt;P&gt;I will indeed, thanks again.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 10:56:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-security-suite-installation/m-p/189234#M10030</guid>
      <dc:creator>jamesy281</dc:creator>
      <dc:date>2014-10-31T10:56:38Z</dc:date>
    </item>
  </channel>
</rss>

