I've seen similar questions, but the answers are vague or don't seem to apply. I have 2 ASAs forwarding their logs. I can search for one and find log data, but the not the other one. I searched through metrics.log, license_usage.log, and splunkd.log. I find data concerning both ASAs in the metrics and license logs, but only the working one in splunkd.log (those are errors about missing timestamp).
In the license_usage.log file, they both show st="cisco:asa" and idx="firewall".
↧