Splunk Search

Lost on ASA syslog config.

isworks
New Member

I have configured the ASA to syslog directly to my splunk server(low volume) and I have set up to receive syslog on UDP 514.
However, I am not getting any data, the Cisco ASA app is not picking it up, etc.
I believe I have everything set up according to the documentation.
I have also searched the community, and the solutions provided have not seemed to help.

A kick in the right direction would be appreciated.

Thanks!

Tags (2)
0 Karma

a212830
Champion

Are you sure that you are getting the syslog messages? Can you confirm it via a tcpdump or snoop? If the forwarder is reading port 514, then I beleive that it needs to run as root.

0 Karma
Get Updates on the Splunk Community!

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...