Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sourcetype cisco:wsa:l4tm documented, but not working #1998

Open
schose opened this issue Feb 6, 2023 · 2 comments
Open

sourcetype cisco:wsa:l4tm documented, but not working #1998

schose opened this issue Feb 6, 2023 · 2 comments

Comments

@schose
Copy link

schose commented Feb 6, 2023

Hi all,

In the sc4s documentation cisco:wsa:l4tm is listed as a usable sourcetype. Splunk Docs also describe it: "to collect data for access logs, W3C logs, and L4TM logs for the Cisco Web Security Appliance, you must use Splunk Connect for Syslog."

In Cisco product documentation "Traffic Monitor Logs | Records sites added to the L4TM block and allow lists. | No | Yes" is listed as "Supports Syslog Push?" -> "No"

On recent v14.5.1-008 there is still no option to send l4tm logs using syslog:
image

can anybody help to clarify if this is a double documentation bug or any hints how to ingest cisco:wsa:l4tm using syslog?

Thanks for all in advance!

Andreas

@bparmar-splunk
Copy link
Contributor

bparmar-splunk commented Feb 7, 2023

Hi @schose,
To ingest Cisco WSA logs, please refer this docs which helps you to configure to route logs to Splunk using SC4S.
Doc link: https://docs.splunk.com/Documentation/AddOns/released/CiscoWSA/Installationsteps

@schose
Copy link
Author

schose commented Feb 7, 2023

Hi @bparmar-splunk ,

just to clarify, in Splunk docs it's stated that you can ingest Traffic Monitor Logs (cisco:wsa:l4tm) using syslog. The Vendor (Cisco) documents that this is not possible. I also try to show in the screenshot that ciscos documenation is right.

My question is: is this is an mistake in your documentation? How do you ensure that sourcestypes listed below "known vendors" are really working?

best regards,

Andreas

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants