Getting Data In

Cisco ASA 5510 - cannot get data

renatac
New Member

Hi,
I´ve installed Splunk App for Cisco ASA version 0.9.6 downloaded today, and cannot see any data.
Cisco is generating syslog and I´ve configured source as syslog over UDP but nothing is shown on app page.
Do you have a conf guide or some useful info that you can send?
Regards,
renatac

Tags (1)
0 Karma

dwaddle
SplunkTrust
SplunkTrust

For starters, are you sure the UDP events are making it into Splunk? I would probably start out with checking some of the following:

  • What port# do you have Splunk set to listen on? If it's < 1024 Splunk needs to be running as root. Check output of (on linux) netstat -anup to make sure it is listening. You may have another process (rsyslog/syslog-ng/etc) already listening on the default UDP syslog port.
  • Use tcpdump to make sure the UDP packets from the ASA are arriving at the Splunk server, on the port you expect them on.
  • If Splunk is listening on the right port and the packets are arriving at the splunk host, is the local host's firewall blocking the udp events?
  • Run a realtime search on "*" and see if you can see these events showing up, perhaps under an unexpected sourcetype

If Splunk is definitely getting the events, then there may be other problems. But you need to make sure the data is getting there first.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...