The documentation of the Cisco Security Cloud Splunk app and the issues I am facing with this app is quite shocking.
- Firstly, no documentation on how to migrate from deprecated Splunk Estreamer addon to this new "app"
- After I installed the app, I keep getting this error even if opened browser in incognito mode. Absolutely zero logs about this.

- Doc mentions the below but there is literally ZERO logs in this file.
Tracks input creation, connectivity to Cisco APIs, and error responses from connectors.
$SPLUNK_HOME/var/log/splunk/CiscoSecurityCloud/CiscoSecurityCloud.log
- After looking at some other posts, seems like this is a pretty common issue but struggled to find a solution to make this work.
- Here they say "Modify the outputs.conf file to store the _internal index locally". Unless in very specific scenarios, no one indexes logs locally on a heavy forwarder in Splunk,
Can someone please help with this ?