I need to configure cisco esa in splunk but Configuration and inputs page does not loads and also I don't have any idea how to integrate this add on in splunk I read documentation and it says that I need to create inputs for monitoring log files but if anyone had practice of integrating cisco esa in splunk and can guide me step by step integration I will be very glad.
Hi @AceX
This app isnt intended to be accessed via the Web UI - therefore the Nav bar you are seeing is from a different app. There is no Input or Configuration page for this app.
Check out https://splunk.github.io/splunk-add-on-for-cisco-esa/ConfigureCiscoESA/ for details on how to setup ESA logging. Depending on the approach you take you could then either setup a inputs.conf monitor stanza or HEC from SC4S for ingestion.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing