Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Ironport Integration with Splunk

Hi;

    I am trying to integrate ironport and splunk for the reporting feature. Have anyone tried with this.

Thanks & Regards

Sreejith R

5 REPLIES
Cisco Employee

Ironport Integration with Splunk

Hi Sreejith

We have few customer being in transition over to Splunk, Please let me know if you have ANY specific questions.

Regards,

Zack

New Member

Ironport Integration with Splunk

Cisco has developed, sells and directly supports a Advanced Reporting for WSA Application for Splunk. 

Not only does the application properly extract the various fields in both access and trafmonlogs, but also directly emulates the functionality of on-box reporting while still allowing for additional Splunk searches.

New Member

Ironport Integration with Splunk

Do you have any proper document for doing this. I downloaded the WSA from cisco and added in the splunk. But its not fetching the information from the ironport. Maybe i missed one or two steps. If you have any documents , please share it. it will be very helpful.

Thanks & Regards

Sreejith R

New Member

Ironport Integration with Splunk

There are Install, User and Troubleshooting Guides posted to the Cisco Support portal.  The "Install Guide" steps one through the process of importing logs, first time set-up, etc.

The "Troubleshooting Guide" will help diagnose any problems you may be having.  In short, I would insure that the data is being properly indexed (search "*" in the logs and make sure fields are properly extracted, eg. acl_tag).

Next, with the fields being properly extracted, you may need a one-time run of the summary script if you have imported historical logs. 

All of this is documented in the guides.

~Tim

Cisco Employee

Re: Ironport Integration with Splunk

Hi Sreejith

Enclosing a step by step document please let me know if you have ANY specific questions after reviewing this.

Regards,

Zack

1941
Views
0
Helpful
5
Replies