Security

Cisco Ironport Searches

aatuckett
New Member

I am trying to run the searches that come with the Ironport Web Security portion of Cisco Security for Splunk, and nothing come up. The logs are being indexed because I can search on eventtype="ironport_proxy", but the prepackaged searches do not impart data. Has anyone had any experience with this? Cheers.

Tags (3)
0 Karma

treinke
Builder

What index is the data going in to? I noticed I had to have mine in the "cisco_wsa" index for it to work.

There are no answer without questions
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...