Greetings. This may be elementary, but I have our Cisco ASA 5516 sending logs via a syslog server to Splunk. I configured a basic inputs.conf file to do so.
The logs get into Splunk but the parsing isn't very good. I seem to have to extract most fields (like I saw in another question re: message_id field.) Shouldn't those fields be parsed automatically? I don't see an AnyConnect TA or app except for NVM which my infrastructure team says we're not using.