Hello all,
I am new to Splunk. I am trying to setup some apps, Cisco Security Suite being one. I am having the same "blank dashboard" issue as others have posted. All panels are showing "No results found." I am having exactly the same problem with another security related Splunk app and it is very frustrating.
I am running Splunk 6.0 on Windows Server 2012. There is only one Splunk server in the landscape. I have multiple ASA firewalls sending syslog to Splunk via UDP 514. I have a custom index receiving syslog data from all network devices, and it is searchable in the Splunk UI. I have confirmed I can see results from ASA. I have installed the TA for ASAs. I have also followed the instructions regarding the TA & SA file & folder configuration, but still nothing.
I am not sure what else to do at this point. Any assistance would be greatly appreciated.
Thank you,
Drew
RSENNETT_SPLUNK. Here are the first 15 lines of the props.conf file per your request. I will post an event shortly.
################ Global ####################
#default port is 514
#[source::tcp:514]
#TRANSFORMS-force_sourcetype_for_cisco = force_sourcetype_for_cisco_asa,force_sourcetype_for_cisco_pix,force_sourcetype_for_cisco_fwsm
[source::udp:514]
TRANSFORMS-force_sourcetype_for_cisco = force_sourcetype_for_cisco_asa,force_sourcetype_for_cisco_pix,force_sourcetype_for_cisco_fwsm
################ ASA ####################
[source::....asa]
sourcetype = cisco:asa
[cisco:asa]
SHOULD_LINEMERGE = false
Well, we can close this out. I did an upgrade from 6.0 to 6.1 yesterday. During this process I removed the CSS & TA folders. After the upgrade, I installed them again, uncommented the UDP port 514 and transform lines, restarted Splunk, and the dashboards are working fine now. We have several ASAs in the environment, all logging to Splunk, so it takes a few minutes for some of the data to load, but it works. Very nice. I am certain our network security and cyber security folks will be happy this has been put to rest. Now, I have to move on to the next one where I am having a similar issue. Thank you for all who responded.