- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which Sourcetype for NGIPS?

morethanyell
Builder
04-08-2022
12:39 PM
The SplunkWorks-built TA called Splunk Add-on for Cisco FireSIGHT said in the description that it is able to parse NGIPS logs. But upon inspection of the `props.conf`, it doesn't have sourcetype for NGIPS. Which should I use? I tried the `cisco:sourcefire` but it's not working.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

morethanyell
Builder
04-12-2022
01:51 AM
Thanks. It did not parse the fields of the logs. I ended up writing our own props for it.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

ragedsparrow
Contributor
04-08-2022
02:05 PM
I think it would be `[cisco:sourcefire:appliance:syslog]`
Also, that TA is out of support. Cisco has released a supported addon to replace it here: https://splunkbase.splunk.com/app/3662/
