I'm having a hard time getting the ironport web data to fill in correctly. I'm very new to splunk so i'm sure thats some of my problem. I have a script that pulls the current access log every half hour or so and then drops it in a directory on my splunk machine. I then added a data import for files and directories and pointed it to this same directory. I know that the ironport app says to make sure the source is set to cisco_wsa. I don't seem to have that in my list of source types. Is there something else I need to download or setup to get that source type to appear for me? Also if anyone has any experience in setting up the ironport web to work with splunk I wouldn't mind hearing any ideas that you might have as well. Thanks in Advance.
Joe