All Apps and Add-ons

Cisco Security Suite blank dashboard - What am I missing?

tsodrew
Explorer

Hello all,

I am new to Splunk. I am trying to setup some apps, Cisco Security Suite being one. I am having the same "blank dashboard" issue as others have posted. All panels are showing "No results found." I am having exactly the same problem with another security related Splunk app and it is very frustrating.

I am running Splunk 6.0 on Windows Server 2012. There is only one Splunk server in the landscape. I have multiple ASA firewalls sending syslog to Splunk via UDP 514. I have a custom index receiving syslog data from all network devices, and it is searchable in the Splunk UI. I have confirmed I can see results from ASA. I have installed the TA for ASAs. I have also followed the instructions regarding the TA & SA file & folder configuration, but still nothing.

I am not sure what else to do at this point. Any assistance would be greatly appreciated.

Thank you,
Drew

RSENNETT_SPLUNK. Here are the first 15 lines of the props.conf file per your request. I will post an event shortly.

################ Global ####################
#default port is 514
#[source::tcp:514]
#TRANSFORMS-force_sourcetype_for_cisco = force_sourcetype_for_cisco_asa,force_sourcetype_for_cisco_pix,force_sourcetype_for_cisco_fwsm
[source::udp:514]
TRANSFORMS-force_sourcetype_for_cisco = force_sourcetype_for_cisco_asa,force_sourcetype_for_cisco_pix,force_sourcetype_for_cisco_fwsm
################ ASA ####################
[source::....asa]
sourcetype = cisco:asa
[cisco:asa]
SHOULD_LINEMERGE = false

1 Solution

tsonms
Engager

Well, we can close this out. I did an upgrade from 6.0 to 6.1 yesterday. During this process I removed the CSS & TA folders. After the upgrade, I installed them again, uncommented the UDP port 514 and transform lines, restarted Splunk, and the dashboards are working fine now. We have several ASAs in the environment, all logging to Splunk, so it takes a few minutes for some of the data to load, but it works. Very nice. I am certain our network security and cyber security folks will be happy this has been put to rest. Now, I have to move on to the next one where I am having a similar issue. Thank you for all who responded.

View solution in original post

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...