Getting Data In

Not able to see the syslogs of ASA on Splunk Web

dineshverma
New Member

Hi All,

I've configured my ASA to send syslog to splunk server installed on centos. I took capture on ASA and I can see packets are leaving the ASA. I took capture on centOS on port 514 and packets are making to the centOS machine as well. For some reason I don't see them on splunk web.

I've created data input for UDP port 514 (all default), Source type (cisco:asa).

I'm really not sure what is the piece of info or config I'm missing here.

I would appreciate your quick help here.

Regards,
Dv

0 Karma

molinarf
Communicator

Are you looking to get data from your firewall for security events? If this is the case, you will need to install the Splunk for Cisco Security App which will provide a dashboard that contains Security Event Statistics, as well as being able to look at a Firewall Overview or Event Search.

0 Karma

xavierashe
Contributor

What are you using to capture the syslog packets on the linux box? syslogd, rsyslog, syslog-ng, or splunk?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...