Is is possible to use the firewall app without the security suite? The reason I ask is that I'd prefer to only use the Firewall app instead of the entire security suite.
When I try to configure the setup of the firewalls app and enter 514 for my UDP port I get the following error:
Encountered the following error while trying to update: In handler 'localapps': Parameter name: UDP port 514 is not available.
When I go to data inputs and manaully specify UDP 514 I see traffic coming to splunk fine from my ASA, the problem is I have no idea how to get it to work with the Cisco For Splunk Firewall App.
Any suggestions?
Splunk for Cisco firewall is an add-on with no landing page.
You need to create an app,drop the Cisco firewall add-on contents in it, then modify the splunk/etc/apps/<your new app>/default/data/ui/nav/default.xml
to display the cisco firewall views in your app.
Regarding UDP this is because it is already in use then your add-on is setup.
Once you copied the add-on contents in your new app just modify/create the splunk/etc/apps/<your new app>/local/app.conf
with the following parameters:
[install]
state = enabled
is_configured = true
[ui]
is_visible = true
Got it resolved, we had to change the event type from our syslogs from cisco_firewall to &cisco_asa.
Also put in the security suite, working now. Kind Regards.
Another issue is no matter what I when I go to manage apps, Setup under Splunk for Cisco Firewalls, the app never shows up under my apps as being available.
Any help is appreciated.