Splunk Enterprise

Cisco security suite splunk v8 distributed

christian_dinh
Loves-to-Learn Lots

Hello, I have Splunk Enterprise v8.1 in distributed cluster with 1 SH, 1 master, 2 indexers and 2 heavy forwarders.  

I have Cisco security suite installed on the HF and the data visualization is displaying correctly.  I am looking for assistance to display the data in the SH.

 

cisco devices send logs to HF.  HF is configured to route traffic to indexers and all is working fine.  Search results showed up on SH but can’t get the Cisco security suite app to display the data.  Any help would be greatly appreciated.

Thanks!

 

Labels (1)
Tags (1)
0 Karma

christian_dinh
Loves-to-Learn Lots

I do get errors relating to Cisco Security App in the /opt/splunk/var/log/splunk/splunkd.log

11-03-2020 09:49:13.617 -0800 WARN HttpListener - Socket error from 127.0.0.1:33412 while accessing /servicesNS/-/Splunk_CiscoSecuritySuite/admin/summarization: Broken pipe

11-03-2020 10:00:46.643 -0800 WARN HttpListener - Socket error from 127.0.0.1:40300 while accessing /servicesNS/-/Splunk_CiscoSecuritySuite/admin/summarization: Broken pipe

11-03-2020 11:00:22.390 -0800 WARN HttpListener - Socket error from 127.0.0.1:44582 while accessing /servicesNS/-/Splunk_CiscoSecuritySuite/admin/summarization: Broken pipe

11-03-2020 12:00:46.430 -0800 WARN HttpListener - Socket error from 127.0.0.1:49260 while accessing /servicesNS/-/Splunk_CiscoSecuritySuite/admin/summarization: Broken pipe

 

 

0 Karma

christian_dinh
Loves-to-Learn Lots

Data input into HF is udp/8515 as sourcetype=cisco::asa

 

HF routes to Indexers over udp:8518.

0 Karma

christian_dinh
Loves-to-Learn Lots

Positive that it is installed on the SH.  No errors on the dashboard, just showing “noo data found”

0 Karma

richgalloway
SplunkTrust
SplunkTrust

An HF is essentially a SH so it the app works in one it should work in the other.  Are you sure it was installed on the SH correctly?  Any error messages on the dashboard or in the logs?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...