<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic received event for unconfigured/disabled/deleted index='firewall' with source='source::udp:5447' host='host::x.x.x.x' sourcetype='sourcetype::cisco:asa' (1 missing total) in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/received-event-for-unconfigured-disabled-deleted-index-firewall/m-p/102313#M7487</link>
    <description>&lt;P&gt;Can't get this working with Splunk for Cisco ASA&lt;/P&gt;

&lt;P&gt;Set ASA 5505 to forward syslog to usp/5447 with timestamps enabled&lt;/P&gt;

&lt;P&gt;:/opt/splunk/etc/apps/Splunk_for_CiscoASA/local/inputs.conf show this:&lt;/P&gt;

&lt;P&gt;[udp://5447]&lt;BR /&gt;
connection_host = ip&lt;BR /&gt;
sourcetype = syslog&lt;/P&gt;

&lt;P&gt;Still get:&lt;BR /&gt;
received event for unconfigured/disabled/deleted index='firewall' with source='source::udp:5447' host='host::x.x.x.x' sourcetype='sourcetype::cisco:asa' (1 missing total)&lt;/P&gt;

&lt;P&gt;This is a vanilla install on Ubuntu 12.04, same issue on Windows 2012 so should not be OS specific.&lt;/P&gt;

&lt;P&gt;I'd really appreciate if someone could bulletpoint steps taken for the benefit of all... thanks! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Did follow install notes:&lt;BR /&gt;
Installation Notes&lt;/P&gt;

&lt;P&gt;Pre-requisites;&lt;BR /&gt;
- TA-cisco_asa (1.1)&lt;BR /&gt;
- SideView Utils (used 1.3.5 not 2.x)&lt;BR /&gt;
- Google Maps(1.1.2)&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 13:11:55 GMT</pubDate>
    <dc:creator>ionitsupport</dc:creator>
    <dc:date>2020-09-28T13:11:55Z</dc:date>
    <item>
      <title>received event for unconfigured/disabled/deleted index='firewall' with source='source::udp:5447' host='host::x.x.x.x' sourcetype='sourcetype::cisco:asa' (1 missing total)</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/received-event-for-unconfigured-disabled-deleted-index-firewall/m-p/102313#M7487</link>
      <description>&lt;P&gt;Can't get this working with Splunk for Cisco ASA&lt;/P&gt;

&lt;P&gt;Set ASA 5505 to forward syslog to usp/5447 with timestamps enabled&lt;/P&gt;

&lt;P&gt;:/opt/splunk/etc/apps/Splunk_for_CiscoASA/local/inputs.conf show this:&lt;/P&gt;

&lt;P&gt;[udp://5447]&lt;BR /&gt;
connection_host = ip&lt;BR /&gt;
sourcetype = syslog&lt;/P&gt;

&lt;P&gt;Still get:&lt;BR /&gt;
received event for unconfigured/disabled/deleted index='firewall' with source='source::udp:5447' host='host::x.x.x.x' sourcetype='sourcetype::cisco:asa' (1 missing total)&lt;/P&gt;

&lt;P&gt;This is a vanilla install on Ubuntu 12.04, same issue on Windows 2012 so should not be OS specific.&lt;/P&gt;

&lt;P&gt;I'd really appreciate if someone could bulletpoint steps taken for the benefit of all... thanks! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Did follow install notes:&lt;BR /&gt;
Installation Notes&lt;/P&gt;

&lt;P&gt;Pre-requisites;&lt;BR /&gt;
- TA-cisco_asa (1.1)&lt;BR /&gt;
- SideView Utils (used 1.3.5 not 2.x)&lt;BR /&gt;
- Google Maps(1.1.2)&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:11:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/received-event-for-unconfigured-disabled-deleted-index-firewall/m-p/102313#M7487</guid>
      <dc:creator>ionitsupport</dc:creator>
      <dc:date>2020-09-28T13:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: received event for unconfigured/disabled/deleted index='firewall' with source='source::udp:5447' host='host::x.x.x.x' sourcetype='sourcetype::cisco:asa' (1 missing total)</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/received-event-for-unconfigured-disabled-deleted-index-firewall/m-p/102314#M7488</link>
      <description>&lt;P&gt;the answer is in the title : &lt;STRONG&gt;received event for unconfigured/disabled/deleted index='firewall'&lt;/STRONG&gt;&lt;BR /&gt;
please create the index "firewall" in your indexer !&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2013 07:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/received-event-for-unconfigured-disabled-deleted-index-firewall/m-p/102314#M7488</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-01-29T07:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: received event for unconfigured/disabled/deleted index='firewall' with source='source::udp:5447' host='host::x.x.x.x' sourcetype='sourcetype::cisco:asa' (1 missing total)</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/received-event-for-unconfigured-disabled-deleted-index-firewall/m-p/102315#M7489</link>
      <description>&lt;P&gt;Thanks, error message is gone. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;But I still don't get anything in Splunk for Cisco ASA app.&lt;BR /&gt;
With all due respect I thought based on the Install notes I could get this working but I must be missing something.&lt;/P&gt;

&lt;P&gt;Firewall index shows 311 events.&lt;/P&gt;

&lt;P&gt;Could you please let me know the next step or point me to a guide?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2013 19:28:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/received-event-for-unconfigured-disabled-deleted-index-firewall/m-p/102315#M7489</guid>
      <dc:creator>ionitsupport</dc:creator>
      <dc:date>2013-01-29T19:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: received event for unconfigured/disabled/deleted index='firewall' with source='source::udp:5447' host='host::x.x.x.x' sourcetype='sourcetype::cisco:asa' (1 missing total)</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/received-event-for-unconfigured-disabled-deleted-index-firewall/m-p/102316#M7490</link>
      <description>&lt;P&gt;I also had this same issue.  To fix it I had to do 2 things.&lt;/P&gt;

&lt;P&gt;1.) Create an index named firewall&lt;BR /&gt;
2.) Add this index to the "Indexes searched by default" section which is under Manager-&amp;gt;Access Controls-&amp;gt;Roles-&amp;gt;Select the appropriate role.&lt;/P&gt;

&lt;P&gt;This was done with v 5.0.4 of Splunk&lt;/P&gt;

&lt;P&gt;I hope this is helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2014 23:08:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/received-event-for-unconfigured-disabled-deleted-index-firewall/m-p/102316#M7490</guid>
      <dc:creator>pmcquaid</dc:creator>
      <dc:date>2014-02-13T23:08:19Z</dc:date>
    </item>
  </channel>
</rss>

