Copy your logs (SCP) from the WSA to an intermediate (syslog) server and then have Splunk pull from there. I primarily use the access_log as it contains the most relevant data, and this is what the Splunk Cisco App is expecting I believe. You can d...
SPAN is just a copy of traffic, so it won't affect the source ports. One option you can use which you alluded to earlier is ECLB:http://cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_example09186a0080671a8d.shtml
What is the software version you are running? You need to supply that. It sounds like sensorApp has crashed for some reason. You may need an upgrade to address a possible bug (if that is what is happening here) but we need to see what version you ...
Try to session into if from the ASA interface:http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids12/cliguide/clilogin.htm#wp1030296From there you can run 'setup' and configure the network parameters. Then you just connect to the ethern...