Skip to content

Installation overview for the Splunk Add-on for Cisco WSA

Install and configure this add-on on your supported platform.

  1. Download the add-on from Splunkbase at http://splunkbase.splunk.com/app/1747/.
  2. Install the add-on.
  3. Work with your Cisco WSA administrator to configure your Cisco WSA server to place the logs on a forwarder or single instance and create a push job.
  4. On the data collection node for the add-on, configure your inputs.
  5. Check Customize log and field extractions for supported sourcetypes for sourcetype specific configuration options and requirements.