cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
27
Views
0
Helpful
1
Replies

Issues With Cisco Security Cloud app

dmaaaa1
Community Member

The documentation of the Cisco Security Cloud Splunk app and the issues I am facing with this app is quite shocking. 

  1. Firstly, no documentation on how to migrate from deprecated Splunk Estreamer addon to this new "app"
  2. After I installed the app, I keep getting this error even if opened browser in incognito mode. Absolutely zero logs about this.
     
    dmaaaa1_1-1785388098622.png
  3. Doc mentions the below but there is literally ZERO logs in this file. 

    Tracks input creation, connectivity to Cisco APIs, and error responses from connectors.

    $SPLUNK_HOME/var/log/splunk/CiscoSecurityCloud/CiscoSecurityCloud.log
  4. After looking at some other posts, seems like this is a pretty common issue but struggled to find a solution to make this work.
  5. Here they say "Modify the outputs.conf file to store the _internal index locally". Unless in very specific scenarios, no one indexes logs locally on a heavy forwarder in Splunk,

Can someone please help with this ?

1 Accepted Solution

Accepted Solutions

dmaaaa1
Community Member

Works well with 4.0.1 version.

View solution in original post

1 Reply 1

dmaaaa1
Community Member

Works well with 4.0.1 version.

Review Cisco Networking for a $25 gift card