All Apps and Add-ons

How to setup to run reports for data from Cisco AS5510 Device

llreilly
New Member

I am new to splunk and need some help is basic terms on how to setup splunk to work with my ASA5510 to be able to report on VPN user login/logout times and data and also users internet useage. I have splunk setup as the syslog server and receiving all the log data from the ASA. I have downloaded the Cisco add ins for WebIron and Firewall but do no know how to get them setup or if they are the correct apps. My ASA has the Trend Micro CSC module. If anyone could please tell me how or if splunk is able to do what I need. I have watched the how to video but it deals more with how to get searches from web servers not how to get info from syslog data.I also have the window event log collecting but that is the next step first I need to get the syslog data working. I appreciate any help.

0 Karma

EmmaJing
New Member

Maybe you can seek the answer on Cisco website.

0 Karma

dleung
Splunk Employee
Splunk Employee

Hi llreilly, if you already have Splunk collecting your Cisco ASA firewall messages via syslog and you have the Splunk for Cisco Firewalls Add-on installed, you only need to make sure those syslog messages are sourcetyped correctly.

You can refer here: http://answers.splunk.com/questions/3366/how-do-i-install-the-cisco-firewall-add-on

There is also additional configuration information contained within the add-ons readme file.

Once you sourcetype the incoming events you will be able to search on those from the Search App. To see Cisco Firewall specific dashboard, install the Cisco Security Suite: http://splunkbase.splunk.com/apps/All/4.x/Suite/app:Cisco+Security+Suite

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...