We are currently running Splunk 5.0.5 together with Splunk Enterprise Security 2.4.1. The Cisco Firewalls (TA-cisco v2.0) app is currently installed. Being that the Add-on for Cisco ASA (3.0) maps firewall data to the CIM, I am considering installing that in place of the TA-cisco 2.0 app.
I am curious if there might be any drawbacks in doing this? Is the upgrade just a question of removing the first app. and then installing the second?