All Apps and Add-ons

Splunk TA For Cisco ASA - event_desc and lookups/event_codes.csv missing

BP9906
Builder

Just upgraded to the Splunk TA for Cisco ASA (previous Cisco Firewall) and noticed that event_desc is missing because event_codes.csv doesnt exist and was never carried over. Any reason why this is the case?

Also the error_code field extraction is missing too.

Doesnt make any sense and I dont see it in the new Cisco Security Suite 3.0 either.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

following up on unanswered questions... the TA has a different knowledge structure than the old app did, and has grown in different ways as newer Splunk versions have become available. The docs describing its current incarnation are here: http://docs.splunk.com/Documentation/AddOns/latest/CiscoASA/Description If you have dashboards or alerts built on older names, you may be able to fieldalias those.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...