Troubleshoot the Splunk Add-on for Cisco ASA
CIM fields are mapped incorrectly after Cisco ASA Cloud Upgrade
If you find noncompliant values for CIM fields after you upgrade the Splunk Add-on for Cisco ASA in your cloud environment, it is likely that lookups have not been upgraded properly. Assuming you have no custom changes added to your lookups, you can replace all the lookup files while upgrading the add-on and not modify the lookups stanzas in props.conf.
Configure inputs for the Splunk Add-on for Cisco ASA
Source types for the Splunk Add-on for Cisco ASA
This documentation applies to the following versions of Splunk® Supported Add-ons: released