Refine your search:

Hi All,

The Splunk for Cisco Firewalls app doesn't seem to extract fields from all different Cisco FWSM syslog types (e.g. %FWSM-4-106100). Searching the knowledge base I found the Cisco ASA/FWSM Field extractions app made by user dps. I can see the props.conf file has got the right extractions. I'm trying to get these extractions into the Splunk for Cisco Firewalls app as I don't want to rename my sourcetype again. Anyone an idea if this will work and what should be the right way to establish this?

Thanks in advance!

/daniel

asked 22 Jun '11, 05:09

ddelange's gravatar image

ddelange
12
accept rate: 0%

edited 04 Jul '11, 04:33


One Answer:

Guess Should work via Aliasing - Below Notes from Cisco Spunk SIEM Doc

The Cisco App add-on will rename the sourcetype of your firewall events to cisco_firewall. If you have previously added Cisco Firewall data as a data source and would like to preserve the current sourcetype for reporting purposes, you can create an alias in the local directory of this app.

Create a sourcetype alias, add the following entry to props.conf under the local directory of this app ($SPLUNK_HOME/etc/apps/cisco_firewall_addon/local):

[cisco_firewall] rename = your_current_firewall_sourcetype

link

answered 26 Oct '11, 04:31

swaminathan's gravatar image

swaminathan
1
accept rate: 0%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×351
×78
×2

Asked: 22 Jun '11, 05:09

Seen: 1,106 times

Last updated: 26 Oct '11, 04:31

Copyright © 2005-2012 Splunk, Inc. All rights reserved.