Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cisco FTD not parsing and TA Doc Issues #2439

Open
harv-qq opened this issue May 3, 2024 · 2 comments
Open

Cisco FTD not parsing and TA Doc Issues #2439

harv-qq opened this issue May 3, 2024 · 2 comments
Assignees

Comments

@harv-qq
Copy link

harv-qq commented May 3, 2024

image

states ASA TA will sort FTD as well

image

states FTD will assign a sourcetype of cisco:ftd

The Cisco ASA TA has no reference for any sourcetype apart from cisco:asa

Additional to this we have added the key to splunk_metadata.csv etc:

cisco_ftd,index,blahblah

Logs end up a mix between cisco:asa and lastchance with sc4s:fallback

Logs start %FTD-* etc and are standard

sc4s version=3.21.0

**Is there a pcap available? no due to security reasons

@harv-qq
Copy link
Author

harv-qq commented May 13, 2024

is there an update on this?

@cwadhwani-splunk
Copy link
Collaborator

cwadhwani-splunk commented May 20, 2024

Hi @harv-qq
We have looked into the issue and here are a couple points regarding the logs not getting classified into cisco:ftd:

  1. The parser is written in such a way that if the log message will start from "%FTD-" and will have "430003" in it, the log will be classified into cisco:ftd source type. But if the log message starts with "%FTD-" but does not have "430003" in it, the log will be classified into cisco:asa source type.
    Could you please check the logs that are being classified in cisco:asa contains "430003" in it or not. If feasible, please send us a sample log.

  2. Could you please send us some sample logs for the logs that are being classified into sc4s:fallback? This will help us to futher debug this issue.

Note: You can send the sample logs over email to cwadhwani@splunk.com

Regarding The Cisco ASA TA has no reference for any sourcetype apart from cisco:asa, I am looking into this.

@cwadhwani-splunk cwadhwani-splunk self-assigned this May 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants