I am ingesting Cisco FTD logs and currently using the Cisco ASA add-on which works fine for a lot of event messages.
Unfortunately it is not working perfect as there is one event message that is not getting recognized by the add-on.
What Splunk supported method is the best for a standardized onboarding with full CIM knowledge?
I do not want to use the estreamer as it is mostly creating issues and is not Splunk supported.
Currently used: "Splunk_TA_cisco-asa-4.2.0"