All Apps and Add-ons

Splunk Add-on for Cisco WSA: How do you parse logs for Cisco WSA v10?

kiran331
Builder

Hi,

Our Web Ironports are on Version 10, the add-on is not working for the logs, Does any one has success in parsing the logs from version 10? Below is the sample event?

1511370115.362 267 11.12.13.145 TCP_MISS_SSL/200 5034 GET https://www.yahoo.com:443/service-worker.js "kiran331@new" DIRECT/www.yahoo.com application/javascript DEFAULT_CASE_12-All_Internal-Employees-NONE-NONE-NONE-DefaultGroup - User-Agent = "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36", Destination-IP = 98.139.180.180, Threat-Reason = -

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

HI

Can you please try "Cisco Security Suite" app on Splunk base? I think extraction defined for WSA in this app will help you.

https://splunkbase.splunk.com/app/525/

Thanks

0 Karma

neilsquires
Engager

I also have the Cisco Security Suite installed. It seems to help with the dashboards but the event log imports are missing the additional fields that are being extracted on a V3.2.4 version of the IronPort WSA plug in.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...