Hello, I have Splunk Enterprise v8.1 in distributed cluster with 1 SH, 1 master, 2 indexers and 2 heavy forwarders.
I have Cisco security suite installed on the HF and the data visualization is displaying correctly. I am looking for assistance to display the data in the SH.
cisco devices send logs to HF. HF is configured to route traffic to indexers and all is working fine. Search results showed up on SH but can’t get the Cisco security suite app to display the data. Any help would be greatly appreciated.
Thanks!
I do get errors relating to Cisco Security App in the /opt/splunk/var/log/splunk/splunkd.log
11-03-2020 09:49:13.617 -0800 WARN HttpListener - Socket error from 127.0.0.1:33412 while accessing /servicesNS/-/Splunk_CiscoSecuritySuite/admin/summarization: Broken pipe
11-03-2020 10:00:46.643 -0800 WARN HttpListener - Socket error from 127.0.0.1:40300 while accessing /servicesNS/-/Splunk_CiscoSecuritySuite/admin/summarization: Broken pipe
11-03-2020 11:00:22.390 -0800 WARN HttpListener - Socket error from 127.0.0.1:44582 while accessing /servicesNS/-/Splunk_CiscoSecuritySuite/admin/summarization: Broken pipe
11-03-2020 12:00:46.430 -0800 WARN HttpListener - Socket error from 127.0.0.1:49260 while accessing /servicesNS/-/Splunk_CiscoSecuritySuite/admin/summarization: Broken pipe
Data input into HF is udp/8515 as sourcetype=cisco::asa
HF routes to Indexers over udp:8518.
Positive that it is installed on the SH. No errors on the dashboard, just showing “noo data found”
An HF is essentially a SH so it the app works in one it should work in the other. Are you sure it was installed on the SH correctly? Any error messages on the dashboard or in the logs?