All Apps and Add-ons

After I install the Splunk Add-on for Cisco ASA, why does the setup button not appear?

kiarashbarzoode
New Member

Hello

After I upload the Splunk Add-on for Cisco ASA, the setup button does not appear.
I checked both version Windows and Linux and also downloaded the add-on again.
How can I fix this problem?

0 Karma

ryanoconnor
Builder

I don't believe the Cisco ASA add-on has any sort of setup page. What exactly are you trying to do? Have you taken a look at the documentation for that add-on?

http://docs.splunk.com/Documentation/AddOns/latest/CiscoASA/Description

0 Karma

kiarashbarzoode
New Member

so how config splunk to use cisco ASA logs?

0 Karma

ryanoconnor
Builder

In order to ingest Cisco ASA logs you'll want to start by sending data via syslog from your Cisco devices. This section of the document covers it but may be a little vague if you've never configured Splunk to receive syslog before, or configured a syslog receiver such as syslog-ng.

http://docs.splunk.com/Documentation/AddOns/latest/CiscoASA/Inputs

I would consider reviewing the below documents if you've never done this before.

http://wiki.splunk.com/Community:Best_Practice_For_Configuring_Syslog_Input
http://www.function1.com/2012/05/syslog-collection-with-splunk

Essentially you'll either setup a syslog receiver such as syslog-ng to drop the syslog events into a file. Then Splunk can monitor the file and place it in the proper sourcetype defined here:

http://docs.splunk.com/Documentation/AddOns/latest/CiscoASA/DataTypes

You can also configure Splunk to accept the input directly, but best practices suggest you use syslog-ng.

Let me know if you have any other questions.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...