Hi,
I know this questiona has been asked before (see link below), however there was no definitive answer if the Splunk app can support Cisco WSA 8.5 logs. Hence the question again:
Does the Splunk Cisco WSA app v 3.1.1 support WSA v 8.5 logs?
Many thanks,
Octavian
https://answers.splunk.com/answers/209169/are-there-any-plans-to-update-the-splunk-add-on-fo.html
It does not at this time.
Hi, we've just released version 3.2.0 with support for 8.0, 8.0.6, and 8.1. We're still working on version 8.5.6.
http://docs.splunk.com/Documentation/AddOns/latest/CiscoWSA/About