Getting Data In

Cisco Firewall App UDP Input

splunkn
Communicator

Is is possible to use the firewall app without the security suite? The reason I ask is that I'd prefer to only use the Firewall app instead of the entire security suite.

When I try to configure the setup of the firewalls app and enter 514 for my UDP port I get the following error:

Encountered the following error while trying to update: In handler 'localapps': Parameter name: UDP port 514 is not available.

When I go to data inputs and manaully specify UDP 514 I see traffic coming to splunk fine from my ASA, the problem is I have no idea how to get it to work with the Cisco For Splunk Firewall App.

Any suggestions?

Tags (1)
0 Karma

MarioM
Motivator

Splunk for Cisco firewall is an add-on with no landing page.

You need to create an app,drop the Cisco firewall add-on contents in it, then modify the splunk/etc/apps/<your new app>/default/data/ui/nav/default.xml to display the cisco firewall views in your app.

App intro

Regarding UDP this is because it is already in use then your add-on is setup.

Once you copied the add-on contents in your new app just modify/create the splunk/etc/apps/<your new app>/local/app.conf with the following parameters:

[install]
state = enabled
is_configured = true

[ui]
is_visible = true
0 Karma

splunkn
Communicator

Got it resolved, we had to change the event type from our syslogs from cisco_firewall to &cisco_asa.

Also put in the security suite, working now. Kind Regards.

0 Karma

splunkn
Communicator

Another issue is no matter what I when I go to manage apps, Setup under Splunk for Cisco Firewalls, the app never shows up under my apps as being available.

Any help is appreciated.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...