Splunk Search

SYS logging an ASA

bazcurtis
Explorer

Hi,

I have installed the Cisco Security suite and Cisco Firewall apps. I have setup UDP port 514 and told the ASA to send the logs to the Splunk server, but I see no data. What have I missed that I have no ASA data in Splunk?

Any help would be most welcome.

Best wishes

Michael

bazcurtis
Explorer

Hi,

Thanks for replying. I deleted the 514 udp port, restarted and then remade the 514 from within Splunk Cisco Firewalls.

I now have data coming into Splunk. What is the best level of logging to set on ASA. Is Information enough? I understand I could generate huge amounts of logs if I wanted to, but what level do most people think is a balance?

Best wishes

Michael

0 Karma

dwaddle
SplunkTrust
SplunkTrust

We run our ASA's in DEBUG logging because that is where the various connection opened / closed messages are logged. And, yes, it does generate substantial data. All of our firewalls (not all splunked at this time unfortunately) generate nearly 10GB/day of logs.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

You could be having firewall issues, if your host running Splunk is also running a firewall (iptables / Windows Defender / etc). You need to make sure UDP:514 is open on your Splunk indexer from a firewall perspective. Also check the output of netstat to make sure that Splunk is listening on port 514. (You did restart Splunk didn't you?)

If this doesn't work out, please update your question with output of show logging on the ASA, as well as your Splunk inputs.conf file and someone will be able to further assist. The easiest way of getting the inputs.conf would be to do a splunk cmd btool --debug inputs list.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...