Getting Data In

Cisco Firewall App UDP Input

splunkn
Communicator

Is is possible to use the firewall app without the security suite? The reason I ask is that I'd prefer to only use the Firewall app instead of the entire security suite.

When I try to configure the setup of the firewalls app and enter 514 for my UDP port I get the following error:

Encountered the following error while trying to update: In handler 'localapps': Parameter name: UDP port 514 is not available.

When I go to data inputs and manaully specify UDP 514 I see traffic coming to splunk fine from my ASA, the problem is I have no idea how to get it to work with the Cisco For Splunk Firewall App.

Any suggestions?

Tags (1)
0 Karma

MarioM
Motivator

Splunk for Cisco firewall is an add-on with no landing page.

You need to create an app,drop the Cisco firewall add-on contents in it, then modify the splunk/etc/apps/<your new app>/default/data/ui/nav/default.xml to display the cisco firewall views in your app.

App intro

Regarding UDP this is because it is already in use then your add-on is setup.

Once you copied the add-on contents in your new app just modify/create the splunk/etc/apps/<your new app>/local/app.conf with the following parameters:

[install]
state = enabled
is_configured = true

[ui]
is_visible = true
0 Karma

splunkn
Communicator

Got it resolved, we had to change the event type from our syslogs from cisco_firewall to &cisco_asa.

Also put in the security suite, working now. Kind Regards.

0 Karma

splunkn
Communicator

Another issue is no matter what I when I go to manage apps, Setup under Splunk for Cisco Firewalls, the app never shows up under my apps as being available.

Any help is appreciated.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...