Getting Data In

What add-on for Cisco Firepower syslog (excluding estreamer)?

ojay
Path Finder

Hi all,

I am ingesting Cisco FTD logs and currently using the Cisco ASA add-on which works fine for a lot of event messages.

Unfortunately it is not working perfect as there is one event message that is not getting recognized by the add-on.

What Splunk supported method is the best for a standardized onboarding with full CIM knowledge?

I do not want to use the estreamer as it is mostly creating issues and is not Splunk supported.

Currently used: "Splunk_TA_cisco-asa-4.2.0"

 

Best 

O.

Labels (3)
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...