Hi,
I´ve installed Splunk App for Cisco ASA version 0.9.6 downloaded today, and cannot see any data.
Cisco is generating syslog and I´ve configured source as syslog over UDP but nothing is shown on app page.
Do you have a conf guide or some useful info that you can send?
Regards,
renatac
For starters, are you sure the UDP events are making it into Splunk? I would probably start out with checking some of the following:
netstat -anup
to make sure it is listening. You may have another process (rsyslog/syslog-ng/etc) already listening on the default UDP syslog port.tcpdump
to make sure the UDP packets from the ASA are arriving at the Splunk server, on the port you expect them on."*"
and see if you can see these events showing up, perhaps under an unexpected sourcetypeIf Splunk is definitely getting the events, then there may be other problems. But you need to make sure the data is getting there first.