All Apps and Add-ons

Timestamps problem with ASA

aniroteg
New Member

Hi,
I'm not able to get a correct timestamps on my netflow v9 exported from my Cisco ASA.
Does anyone have a fixup ?

Thanks.

0 Karma

NetFlow_Logic
Contributor

Cisco ASA support is coming in future versions of the NetFlow Integrator. It is a streaming technology that converts NetFlow to syslog, thus making it available in Splunk in real time. Sign up for Beta now. Demo App is here:

http://splunk-base.splunk.com/apps/NetFlow-based+Network+Monitoring+(Beta)

tmontague
New Member

I was having the same issue. After some searching I found that the nfdump doesn't fully support Cisco ASAs in the current stable branches. The only branch that supports ASAs is the NSEL branch. See the sourceforge page here: http://sourceforge.net/projects/nfdump/. "For CISCO ASA devices, which export Netflow Security Event Loging (NSEL) records, please use nfdump-1.5.8-2-NSEL."

0 Karma

NetFlow_Logic
Contributor

Cisco ASA support by the NetFlow Integrator is coming in two weeks. Please contact us if you are interested.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...