All Apps and Add-ons
Highlighted

How to set up the Splunk Add-on for Cisco ASA on a Windows server?

New Member

Dear all,
I'm a newbie:)
Is there anybody that can help run me through the step by step process to set up the Splunk Add-on for Cisco ASA on a Windows Server?

Many thanks!

0 Karma
Highlighted

Re: How to set up the Splunk Add-on for Cisco ASA on a Windows server?

New Member

Would be interested in this as well. I HAD it working but upgraded to v3.1.0 of the Splunk TA Add-on for cisco ASA and that broke everything.

0 Karma
Highlighted

Re: How to set up the Splunk Add-on for Cisco ASA on a Windows server?

Splunk Employee
Splunk Employee

Hi, the key to understanding this is that the ASA add-on doesn't gather data, it models it. You need to configure Splunk to receive the data and set a sourcetype that tells the knowledge mapping in the Addon to apply.

If your devices are already configured to write logs into a syslog server, you can just monitor the directory. If you are starting from scratch, you can have the devices send syslog straight to Splunk by adding a network input.

0 Karma
Highlighted

Re: How to set up the Splunk Add-on for Cisco ASA on a Windows server?

New Member

You did NOT answer his question.

0 Karma
Highlighted

Re: How to set up the Splunk Add-on for Cisco ASA on a Windows server?

Splunk Employee
Splunk Employee

Hi, that's a good reason to use the down-vote button to the left of my answer.