Monitoring Splunk

received event for unconfigured/disabled/deleted index='firewall' with source='source::udp:5447' host='host::x.x.x.x' sourcetype='sourcetype::cisco:asa' (1 missing total)

ionitsupport
New Member

Can't get this working with Splunk for Cisco ASA

Set ASA 5505 to forward syslog to usp/5447 with timestamps enabled

:/opt/splunk/etc/apps/Splunk_for_CiscoASA/local/inputs.conf show this:

[udp://5447]
connection_host = ip
sourcetype = syslog

Still get:
received event for unconfigured/disabled/deleted index='firewall' with source='source::udp:5447' host='host::x.x.x.x' sourcetype='sourcetype::cisco:asa' (1 missing total)

This is a vanilla install on Ubuntu 12.04, same issue on Windows 2012 so should not be OS specific.

I'd really appreciate if someone could bulletpoint steps taken for the benefit of all... thanks! 🙂

Did follow install notes:
Installation Notes

Pre-requisites;
- TA-cisco_asa (1.1)
- SideView Utils (used 1.3.5 not 2.x)
- Google Maps(1.1.2)

Tags (1)
0 Karma

pmcquaid
Engager

I also had this same issue. To fix it I had to do 2 things.

1.) Create an index named firewall
2.) Add this index to the "Indexes searched by default" section which is under Manager->Access Controls->Roles->Select the appropriate role.

This was done with v 5.0.4 of Splunk

I hope this is helpful.

yannK
Splunk Employee
Splunk Employee

the answer is in the title : received event for unconfigured/disabled/deleted index='firewall'
please create the index "firewall" in your indexer !

0 Karma

ionitsupport
New Member

Thanks, error message is gone. 😉

But I still don't get anything in Splunk for Cisco ASA app.
With all due respect I thought based on the Install notes I could get this working but I must be missing something.

Firewall index shows 311 events.

Could you please let me know the next step or point me to a guide?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...