All Apps and Add-ons

Cisco Security Suite 3.1.1/3.1.2 compatibility with Splunk 6.6.3

shamscw
Engager

Hi Guys,

I'm trying to get the Cisco Security Suite App installed (https://splunkbase.splunk.com/app/525/) after adding on:

https://splunkbase.splunk.com/app/1620/

It seems to install up until the point of getting to the setup screen for the dashboard and when I go into the app i don't see any data coming in. Please see attached picturealt text

0 Karma

wahmad_splunk
Splunk Employee
Splunk Employee

Cisco Security Suite 3.1.2 is compatible with Splunk 6.6,x and 7.0 - The setup issue you are seeing a known limitation, check out the workaround for this here: https://answers.splunk.com/answers/523408/cisco-security-suite-setup-failure.html

0 Karma

shamscw
Engager

It turns out the severity level on the device was not high enough to send any logs, once fixed I could see data in the cisco security app. I guess the above error can be ignored!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...