Getting Data In

Cisco Anyconnect via Syslog


Greetings. This may be elementary, but I have our Cisco ASA 5516 sending logs via a syslog server to Splunk. I configured a basic inputs.conf file to do so.

The logs get into Splunk but the parsing isn't very good. I seem to have to extract most fields (like I saw in another question re: message_id field.) Shouldn't those fields be parsed automatically? I don't see an AnyConnect TA or app except for NVM which my infrastructure team says we're not using.

Any guidance would be much appreciated.


0 Karma

Re: Cisco Anyconnect via Syslog

Esteemed Legend

You have to install the Splunk Add-on for Cisco ASA:

View solution in original post

0 Karma