I have two index node cluster and one dedicated search head for ES APP. installed Splunk_TA for cisco ASA on the forwarders, indexers and search head . we are able to index the data with sourcetype=cisco:asa.
When we search the data with search app we are able to get all the fields properly including the TAGs required for ES APP. (Ex: src, dst, network etc)
but when we open with data models in the ES APP, most of the fields are showing unknown value. how to troubleshoot this