<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SYS logging an ASA in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/SYS-logging-an-ASA/m-p/41651#M178988</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have installed the Cisco Security suite and Cisco Firewall apps. I have setup UDP port 514 and told the ASA to send the logs to the Splunk server, but I see no data. What have I missed that I have no ASA data in Splunk?&lt;/P&gt;

&lt;P&gt;Any help would be most welcome.&lt;/P&gt;

&lt;P&gt;Best wishes&lt;/P&gt;

&lt;P&gt;Michael&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jul 2011 18:28:57 GMT</pubDate>
    <dc:creator>bazcurtis</dc:creator>
    <dc:date>2011-07-12T18:28:57Z</dc:date>
    <item>
      <title>SYS logging an ASA</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SYS-logging-an-ASA/m-p/41651#M178988</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have installed the Cisco Security suite and Cisco Firewall apps. I have setup UDP port 514 and told the ASA to send the logs to the Splunk server, but I see no data. What have I missed that I have no ASA data in Splunk?&lt;/P&gt;

&lt;P&gt;Any help would be most welcome.&lt;/P&gt;

&lt;P&gt;Best wishes&lt;/P&gt;

&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2011 18:28:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SYS-logging-an-ASA/m-p/41651#M178988</guid>
      <dc:creator>bazcurtis</dc:creator>
      <dc:date>2011-07-12T18:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: SYS logging an ASA</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SYS-logging-an-ASA/m-p/41652#M178989</link>
      <description>&lt;P&gt;You could be having firewall issues, if your host running Splunk is also running a firewall (iptables / Windows Defender / etc).  You need to make sure UDP:514 is open on your Splunk indexer from a firewall perspective.  Also check the output of &lt;CODE&gt;netstat&lt;/CODE&gt; to make sure that Splunk is listening on port 514.  (You did restart Splunk didn't you?)&lt;/P&gt;

&lt;P&gt;If this doesn't work out, please update your question with output of &lt;CODE&gt;show logging&lt;/CODE&gt; on the ASA, as well as your Splunk &lt;CODE&gt;inputs.conf&lt;/CODE&gt; file and someone will be able to further assist.  The easiest way of getting the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; would be to do a &lt;CODE&gt;splunk cmd btool --debug inputs list&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2011 20:06:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SYS-logging-an-ASA/m-p/41652#M178989</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2011-07-12T20:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: SYS logging an ASA</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SYS-logging-an-ASA/m-p/41653#M178990</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Thanks for replying. I deleted the 514 udp port, restarted and then remade the 514 from within Splunk Cisco Firewalls.&lt;/P&gt;

&lt;P&gt;I now have data coming into Splunk. What is the best level of logging to set on ASA. Is Information enough? I understand I could generate huge amounts of logs if I wanted to, but what level do most people think is a balance?&lt;/P&gt;

&lt;P&gt;Best wishes&lt;/P&gt;

&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2011 17:02:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SYS-logging-an-ASA/m-p/41653#M178990</guid>
      <dc:creator>bazcurtis</dc:creator>
      <dc:date>2011-07-18T17:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: SYS logging an ASA</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SYS-logging-an-ASA/m-p/41654#M178991</link>
      <description>&lt;P&gt;We run our ASA's in DEBUG logging because that is where the various connection opened / closed messages are logged.  And, yes, it does generate substantial data.  All of our firewalls (not all splunked at this time unfortunately) generate nearly 10GB/day of logs.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2011 20:20:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SYS-logging-an-ASA/m-p/41654#M178991</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2011-07-18T20:20:20Z</dc:date>
    </item>
  </channel>
</rss>

