Getting Data In

Cisco ESA Add-On Not Parsing

New Member

A log subscription is set on the Cisco ESA appliance (IronPort Text Mail Logs) which is set to forward to a syslog-ng server, which then writes to a unique file. The inputs.conf is configured to monitor the file path. Splunk ingests the data, but fields are not extracting.

Has anyone ran into this issue and has a workaround?

Labels (1)
Tags (1)
0 Karma

Have you installed the Cisco ESA app on the indexers and search heads?
If this reply helps you, an upvote would be appreciated.
0 Karma