Hi,
I wanted to know how the ASA logs/ PIX logs from Cisco devices are fed to Splunk for Cisco ASA app? Can we use the TCP port for uploading?
Can anybody also share a sample ASA logs so that I can gain knowledge about its structure and try to run the app,as I am unable to get the sample files on web.
Please Help...!!!
You can deliver ASA logs to either a Splunk index or a Splunk Universal Forwarder (which will then forward data to the Splunk index). Here is the command to configure your device:
logging host <int> <ipaddr> tcp/514
The
Also, there are sample logs within the add-on located in the samples directory.