I've just installed the Cisco ASA app, along with the 3 prerequisites. I'm running Splunk 5.02 on an Ubuntu server.
In Data Inputs, I added an entry for UDP, port 514 & set the source type to 'cisco:asa'
I added an index named 'firewall'
My ASA is running version 8.4(3)8.
In Logging (Configuration) Logging Setup is enabled.
Logging Filters: the Syslog Servers - Filter Severity is set to Notification
Syslog Servers: I added an entry for my Splunk server to UDP port 514
When I go to the app in Splunk, there is no data. I then went to my Ubuntu server & did a TCPdump on port 514 - lots of data coming in.
I cannot determine if the problem is with the configuration of my ASA or the installation of the app in Splunk.
Any suggestions will be appreciated.
Fixed the problem.
I created the index & specified a unique index 'firewall'. I re-installed & did not name the index. The app appears to be working now. I may have to modify the settings on the firewall, but so far so good.