
Release notes for the Splunk Add-on for Cisco ASA
Version 5.1.0 of the Splunk Add-on for Cisco ASA was released on July 14, 2022.
Compatibility
Version 5.1.0 of the Splunk Add-on for Cisco ASA is compatible with the following software, CIM versions, and platforms.
Splunk platform versions | 8.1, 8.2 |
CIM | 4.20.2 |
Supported OS for data collection | OS independent |
Vendor products | Cisco ASA v9.12, v9.13,v9.16 |
Supported Cisco ASA event message_ids | 106001, 106006, 106007, 106012, 106014, 106015, 106016, 106017, 106020, 106021, 106023, 106100, 106103, 109025, 110002, 110003, 111001, 111004, 111008, 111009, 111010, 113004, 113005, 113008, 113009, 113011, 113012, 113019, 113039, 302010, 302013, 302014, 302015, 302016, 302020, 302021, 303002, 304001, 305009, 305010, 305011, 305012, 305013, 313001, 313004, 313005, 313009, 338002, 338301, 338302, 400013, 400032, 405001, 419002, 419003, 500003, 500004, 502101, 502102, 502103, 502111, 502112, 505004, 505009, 505010, 505011, 505012, 505013, 505014, 505015, 505016, 602303, 602304, 605005, 609001, 609002, 611101, 710002, 710003, 710005, 711004, 713041, 713049, 713075, 713119, 713120, 713130, 713166, 713167, 713172, 713184, 713185, 713198, 713199, 713228, 713903, 713905, 713906, 715001, 715009, 715038, 715046, 715065, 715076, 715080, 716001, 716002, 716038, 716039, 716058, 716059, 717009, 717016, 717022, 717024, 717025, 717027, 717028, 717029, 717030, 717036, 717037, 717056, 720041, 722001, 722003, 722010, 722011, 722012, 722022, 722023, 722028, 722029, 722030, 722031, 722032, 722033, 722034, 722037, 722041, 722051, 722055, 725003, 725007, 725008, 725010, 725011, 725014, 725017, 733100, 734001, 737001, 737003, 737006, 737016, 737026, 737034, 737035, 746012, 746013, 746014, 746015, 746016, 751025, 771002 |
The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.
For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.
New or changed features
The Splunk Add-on for Cisco ASA 5.1.0 introduces the following field changes.
Source-type | message_id, sourcetype | Fields added | Fields removed |
---|---|---|---|
['cisco:asa']
|
602303, 717022, 109031, 106007, 611101, 717027, 113004, 722022, 313001, 505009, 710003, 722028, 113012, 400032, 302014, 722031, 716047, 713185, 302020, 313005, 106014, 302015, 502102, 110003, 716059, 716039, 106017, 717029, 111010, 109025, 303002, 313009, 305011, 772003, 502111, 722051, 106023, 722030, 500003, 106006, 716002, 502112, 106015, 716001, 772002, 505004, 722029, 716058, 106021, 110002, 505015, 400013, 106100, 717028, 722033, 106016, 717009, 722023, 751025, 419003, 605005, 713198, 713228, 302013, 405001, 502103, 338002, 710002, 725003, 113008, 419002, 710005, 725007, 722037, 713167, 106020, 106012, 502101, 113019, 716038, 722034, 717037, 106103, 713166, 313004, 602304, 113005, 605004, 106001, 338301, 113039cisco:asa | ||
['cisco:asa']
|
111001cisco:asa | status, change_type, action, tag::eventtype, change_description, command, eventtype, result, object, dest, object_type, tag, object_id, object_category, Cisco_ASA_action | device, src_host |
['cisco:asa']
|
111004cisco:asa | status, action, tag::eventtype, command, eventtype, result, object, dest, tag, object_category, Cisco_ASA_action | src_host |
['cisco:asa']
|
111009cisco:asa | status, change_type, tag::eventtype, change_description, eventtype, result, object, dest, object_type, tag, object_category | Cisco_ASA_vendor_action, vendor_action |
['cisco:asa']
|
113021cisco:asa | ||
['cisco:asa']
|
302021, 305012, 305013cisco:asa | tag, eventtype, tag::eventtype | |
['cisco:asa']
|
609002, 609001cisco:asa | zone, src_ip, tag::eventtype, eventtype, dest, tag, communication_protocol, dest_ip | IP, zone_name, ip_address |
['cisco:asa']
|
771002cisco:asa | status, change_type, action, tag::eventtype, change_description, command, object_attrs, result, eventtype, object, dest, object_type, tag, object_id, object_category, Cisco_ASA_action | after_time, src_ip, before_time |
['cisco:asa']
|
772004cisco:asa |
Fixed issues
Version 5.1.0 of the Splunk Add-on for Cisco ASA fixes the following issues:
Known issues
Version 5.1.0 of the Splunk Add-on for Cisco ASA has the following known issues:
Third-party software attributions
Version 5.1.0 of the Splunk Add-on for Cisco ASA does not incorporate any third-party software or libraries.
PREVIOUS Lookups for the Splunk Add-on for Cisco ASA |
NEXT Release history for the Splunk Add-on for Cisco ASA |
This documentation applies to the following versions of Splunk® Supported Add-ons: released, released
Feedback submitted, thanks!