Splunk Security Essentials shows the city has Cisco ASA events, but CIM Network_Traffic fields are empty. What pair of actions is the best-practice path?
Select an answer to reveal the explanation.
Short Explanation
Seeing the packets is step one; teaching Splunk their names is step two. The supported ASA add-on is the bridge from we have syslog to CIM Network_Traffic. Assessment without the TA leaves the dashboards blank.
Full Explanation
Data-source assessment and installing the Splunk-supported technical add-on are a pair: the TA maps that sourcetype into CIM. Without it, ASA events can index while Network_Traffic and Security Domain views stay empty. Inventing a city-specific CIM model, filing a decorative notable, or forcing Windows parsers onto syslog is not the supported path. Analysts identify the TA gap; engineers install and deploy it.