All Apps and Add-ons

Splunk Add-on for Cisco WSA: How do you parse logs for Cisco WSA v10?

kiran331
Builder

Hi,

Our Web Ironports are on Version 10, the add-on is not working for the logs, Does any one has success in parsing the logs from version 10? Below is the sample event?

1511370115.362 267 11.12.13.145 TCP_MISS_SSL/200 5034 GET https://www.yahoo.com:443/service-worker.js "kiran331@new" DIRECT/www.yahoo.com application/javascript DEFAULT_CASE_12-All_Internal-Employees-NONE-NONE-NONE-DefaultGroup - User-Agent = "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36", Destination-IP = 98.139.180.180, Threat-Reason = -

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

HI

Can you please try "Cisco Security Suite" app on Splunk base? I think extraction defined for WSA in this app will help you.

https://splunkbase.splunk.com/app/525/

Thanks

0 Karma

neilsquires
Engager

I also have the Cisco Security Suite installed. It seems to help with the dashboards but the event log imports are missing the additional fields that are being extracted on a V3.2.4 version of the IronPort WSA plug in.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...