Getting Data In

Issues With Cisco Security Cloud app

dm1
Contributor

The documentation of this app and the issues I am facing with this app is quite shocking. 

  1. Firstly, no documentation on how to migrate from deprecated Estreamer addon to this new "app"
  2. After I installed the app, I keep getting this error even if opened browser in incognito mode
    dm1_0-1785386070674.png
  3. Doc mentions the below but there is literally ZERO logs in this file. 

    Tracks input creation, connectivity to Cisco APIs, and error responses from connectors.

    $SPLUNK_HOME/var/log/splunk/CiscoSecurityCloud/CiscoSecurityCloud.log
  4. After looking at some other posts, seems like this is a pretty common issue but struggled to find a solution to make this work.
  5. Here they say "Modify the outputs.conf file to store the _internal index locally" Pretty strange

Can someone please help with this ?

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...