All Apps and Add-ons

Cisco Networks App - No ASA details

FraserC1
Path Finder

Hi,

I have installed the Cisco Networks App for Splunk Enterprise and I have data coming in from one switch and one ASA.
In the app, I can only see events from the switch and none from the ASA and I cannot figure out why. I can see events from the ASA coming in without any issue on the search.
I also have the cisco ASA add-on installed, will this be causing any issues at all?

Cheers,

0 Karma

hnorvik
Explorer

You need the Cisco Security Suite app to support the Cisco ASA.
https://splunkbase.splunk.com/app/525
(Sorry I posted my answer in the wrong place)

0 Karma

hnorvik
Explorer

You need the Cisco Security Suite app to support the Cisco ASA.

Since this is an "umbrella" type app, you will also get support for WSA, ESA, ISE, IPS and sourcefire. You have to install all the Add-ons required for those too. See https://splunkbase.splunk.com/app/525

Get Updates on the Splunk Community!

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...