All Apps and Add-ons

Problems with Cisco Security Suite not parsing fields correctly.

yumology
Path Finder

I am running 4.2 build 96430. I have Cisco Security Suite 1.0.0 installed as an App.

I am sending a lot of Cisco ASA and PIX firewall data to Splunk. The hosts are showing up and the sourcetype is cisco_syslog, but it does not parse any of the fields correctly. For instance, I can't search on src_ip or eventtype=firewall-deny.

I have found that a workaround to this is to uninstall the Suite and install the individual packages within it, like Splunk for Cisco Firewalls. Can someone tell me how to get the Suite working?

0 Karma
1 Solution

hazekamp
Builder

yumology,

The Cisco Security Suite app provides navigation and dashboard/report components on top of data collected by the individual Cisco add-ons. Cisco Security Suite is dependent on individual Cisco add-ons such as Cisco Firewalls to bring data in and normalize it correctly. If you are not interested in the dashboards/reports provided by the Suite and just want to leverage things like eventtypes and field extractions, you can opt to just run the add-ons.

View solution in original post

0 Karma

yumology
Path Finder

Hazedav: That absolutely solved my question. Thanks, however, now I'm hitting a new problem. I had Splunk for Cisco Firewalls and Splunk for Cisco IPS apps already installed. Upon trying to install the Suite again I had this error during setup:

Your entry was not saved. The following error was reported: Invalid JSON:




{"status": "OK", "msg": "Successfully updated \"Splunk_CiscoSecuritySuite\". ", "redirect": ""} .

And when I navigate to the app itself in Splunk to see the cool reports and graphs I get errors on each pane like:

Unable to find eventtype ironport'

Error loading file: Error loading file: /static/app/Splunk_CiscoSecuritySuite/ammap/realtime_ammap_settings.xml

Results Error: Error #2032

0 Karma

hazekamp
Builder

I have not seen this before. I would definitely get this to support@splunk.com

0 Karma

hazekamp
Builder

yumology,

The Cisco Security Suite app provides navigation and dashboard/report components on top of data collected by the individual Cisco add-ons. Cisco Security Suite is dependent on individual Cisco add-ons such as Cisco Firewalls to bring data in and normalize it correctly. If you are not interested in the dashboards/reports provided by the Suite and just want to leverage things like eventtypes and field extractions, you can opt to just run the add-ons.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...