All Apps and Add-ons

Technology Add-on for Cisco Secure Access Control Server (ACS): Why am I unable to see any data after installing the add-on?

euroa
Engager

I installed the Technology Add-on for Cisco Secure Access Control Server (ACS) to a heavy forwarder and pointed the Cisco ACS device to send data to the heavy forwarder via udp 9010. I created an inputs.conf file with the following :

[udp://9010]
connection_host = dns
disabled = 0
followTail = 0
sourcetype = cisco:acs
crcSalt = 
index = cisco_secure_acs

and ensured that the port is opened however I am still unable to see any data in the index. Anyone have any ideas?

0 Karma

woodcock
Esteemed Legend

Sniff the port with tcpdump and see if the traffic is getting there. If missing, make sure that the sender is using UDP, not TCP and make sure that ACL/firewall/routes/etc. are allowing the traffic. But you should not be sending directly to Indexers, you should be sending to a syslog aggregator like syslog-ng and doing this:

http://www.georgestarcher.com/splunk-success-with-syslog/

0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...