Hello All,
Splunk Version: v6.2.2
Add-On: Cisco Web Security Advanced Reporting 4.5.0
I have configured the WSA Add-on for Access, TrafMon, and AMP logs to be sent to the WSA. If I check the directories where these logs are being FTP'ed from the WSA, I can see tons of files in all 3 of them.
However, when I navigate to the Advanced Malware Dashboards (all of them), they all show no results in each section of every AMP dashboard.
Any idea why this is happening? Our license covers: wsa_trafmonlogs, wsa_accesslogs, wsa_w3clogs, wsa_syslog, wsa_amplogs, ciscocws
Any help would be appreciated!
Thanks in Advance,
Matt
... View more