Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Copy your logs (SCP) from the WSA to an intermediate (syslog) server and then have Splunk pull from there. I primarily use the access_log as it contains the most relevant data, and this is what the Splunk Cisco App is expecting I believe. You can d...
SPAN is just a copy of traffic, so it won't affect the source ports. One option you can use which you alluded to earlier is ECLB:http://cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_example09186a0080671a8d.shtml
What is the software version you are running? You need to supply that. It sounds like sensorApp has crashed for some reason. You may need an upgrade to address a possible bug (if that is what is happening here) but we need to see what version you ...
Try to session into if from the ASA interface:http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids12/cliguide/clilogin.htm#wp1030296From there you can run 'setup' and configure the network parameters. Then you just connect to the ethern...