I created a data input on Port 514/UDP and the data goes to an index called "cisco_ironport_wsa" and I set the sourcetype to "cisco_wsa_squid" manually. Unfortunately I don't see anything if I choose one of the saved searches. Any idea?
Splunkversion 4.3.3, build 128297
same here.. we changed to ftp transfer logfiles instead, which seems to work
Today we did a few test again and we found that Syslog over TCP or UDP doesn't work with the Cisco Ironport Web Security App. If we use a file monitor as input we got it running. Anynone who knows about that issue?
are you sure your WSA is in wsa_squid
format? WSA can be in different format ie cisco_wsa_squid
, cisco_wsa_w3c
...