Hello!
I think after upgrading to splunk 6, the fields "on the left side" dont have source and destination "mapped" to the src and dst fields in this Cisco Asa log.
Help! 🙂
-Frode
Oct 9 08:37:07 10.255.14.18 %ASA-4-106023: Deny udp src NC03_Link_172.18.246.64_29:xx.175.20.42/61101 dst Link_nett_172.18.241.0_249:xx.175.37.104/623 by access-group "NC03_Link_172.18.246.64_29_access_in" [0x0, 0x0]
Same here 😞