Getting Data In

Is there an example transforms for Splunk for Cisco Firewalls app?

awsdcuser
Explorer

I have Splunk for Cisco Firewalls app v2.0 installed. It is generating some warning messages in the logs: WARN SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='ciscosyslog-src_dom_addr_port_2'; WARN SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='ciscosyslog-dst_dom_addr_port_2'; and WARN SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='product_static_IDS'. Are there any samples of stanzas (or example transforms.conf) for these transforms?

1 Solution

agrant
Explorer

Looks like there is either two missing transforms in default/transforms.conf or the props.conf should be corrected not to call the two _2 transforms.

Namely: ciscosyslog-src_dom_addr_port_2, ciscosyslog-dst_dom_addr_port_2

Perhaps this was a copy/paste error by the developer. For now I'm going to simply remove the transform calls.

View solution in original post

0 Karma

agrant
Explorer

Looks like there is either two missing transforms in default/transforms.conf or the props.conf should be corrected not to call the two _2 transforms.

Namely: ciscosyslog-src_dom_addr_port_2, ciscosyslog-dst_dom_addr_port_2

Perhaps this was a copy/paste error by the developer. For now I'm going to simply remove the transform calls.

0 Karma

awsdcuser
Explorer

Of the three transforms, I did manage to "fix" two of them while working on a solution for my environment for this problem: http://splunk-base.splunk.com/answers/8006/cisco-app-pix-inbound-vs-outbound. I have not revisited the other to see if I want to just remove the transform call or find/create a transform to use.

Thanks.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...