All Apps and Add-ons

Cisco Security Suite 3.1.1/3.1.2 compatibility with Splunk 6.6.3

shamscw
Engager

Hi Guys,

I'm trying to get the Cisco Security Suite App installed (https://splunkbase.splunk.com/app/525/) after adding on:

https://splunkbase.splunk.com/app/1620/

It seems to install up until the point of getting to the setup screen for the dashboard and when I go into the app i don't see any data coming in. Please see attached picturealt text

0 Karma

wahmad_splunk
Splunk Employee
Splunk Employee

Cisco Security Suite 3.1.2 is compatible with Splunk 6.6,x and 7.0 - The setup issue you are seeing a known limitation, check out the workaround for this here: https://answers.splunk.com/answers/523408/cisco-security-suite-setup-failure.html

0 Karma

shamscw
Engager

It turns out the severity level on the device was not high enough to send any logs, once fixed I could see data in the cisco security app. I guess the above error can be ignored!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...