Getting Data In

Cisco Security Suite and Cisco Firewall Add-on Installation

jocogov
New Member

I have installed both Cisco Security Suite and Cisco Firewall Add-On, I have UDP 514 port excepting log data from a Syslogs server. I can view realtime data in the Cisco Firewall app, but no results in the Cisco Security Suite. Is there something I'm missing?

Tags (1)
0 Karma

f10353
New Member

I am also in the same predicament that the Cisco Security Overview does not display Global Security Events, Top Threats, Top Sources, Top Destinations, Top Services, Security Event Statistics by Sourcetype and Security Event Statistics by Host

0 Karma

dapatter75
New Member

Hi I have the same issue and my sourcetype is cisco::asa??

0 Karma

shogan_splunk
Splunk Employee
Splunk Employee

After running into the same issue, the sourcetype renaming is probably not occurring because the regular expression used to force the sourcetype was changed from the previous version of the Splunk for Firewall app. Below shows what the previous version had specified in the transforms.conf, and what it was changed to.

It was updated

  • FROM:

[force_sourcetype_for_cisco_asa]

DEST_KEY = MetaData:Sourcetype

REGEX = %ASA-\d+-\d+

FORMAT = sourcetype::cisco_asa

  • TO:

[force_sourcetype_for_cisco_asa]

DEST_KEY = MetaData:Sourcetype

#REGEX = %ASA-\d+-\d+

REGEX = %ASA--\d+-\d+

FORMAT = sourcetype::cisco_asa

Note the extra - in the Regex.

So to change this, just create a transforms.conf in $SPLUNK_HOME/etc/apps/Splunk_CiscoFirewalls/local, if not already there, and update the REGEX string.

0 Karma

idsersupport
Explorer

I get the same thing here, it worked before the update. I hope some one fixes this.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...