The SplunkWorks-built TA called Splunk Add-on for Cisco FireSIGHT said in the description that it is able to parse NGIPS logs. But upon inspection of the `props.conf`, it doesn't have sourcetype for NGIPS. Which should I use? I tried the `cisco:sourcefire` but it's not working.
Thanks. It did not parse the fields of the logs. I ended up writing our own props for it.
I think it would be `[cisco:sourcefire:appliance:syslog]`
Also, that TA is out of support. Cisco has released a supported addon to replace it here: https://splunkbase.splunk.com/app/3662/