All Apps and Add-ons

Splunk Enterprise not recognizing Splunk Add-on for Cisco ESA

splunkcw17
New Member

Hi All,

I'm trying to install the Cisco ESA Add-on App https://splunkbase.splunk.com/app/1761/

However when setting this up in Cisco Security Suite, it doesn't recognize the app after I've uploaded it - please see screenshots.

It does however recognize it when configuring a data input, please could you advise?

Thanks!

alt text

0 Karma

diogofgm
SplunkTrust
SplunkTrust

the cisco:esa:legacy means you had an older version of the add-on installed before the source types were renamed to follow best practices, your events indexed with the older source types cisco_esa and cisco:esa are now searchable under this new source type.

About data not being visible the email dashboards, there rely on event type = cisco-esa. check your data and see if the event type is present. if you have the latest version of the add-on, they should be.

the eventtype uses this search
(sourcetype="cisco:esa:textmail" OR sourcetype=cisco:esa:legacy) AND (MID OR ICID OR DCID)

Try it and see if you get any results.

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma

khalidrucker
New Member

Hello, can you please advise on how you bypassed the original error, "No data found. Please install this add-on"?

0 Karma

splunkcw17
New Member

I've got the ESA add-on app loaded and visible in Cisco Security Suite, however ESA logs appear in the main security suite dashboard (with cisco:esa:legacy sourcetype) but not in the 'email security' tab - any ideas on this please?

Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...