Cisco Cisco Web Security Appliance S690 Installation Guide

Page of 30
 
1-12
Cisco Advanced Web Security Reporting 5.0 Installation, Setup, and User Guide
 
Chapter 1      Installation and Setup
Set Up On-going Data Transfers
Configure Data Inputs for WSA Logs
Note
To configure data input from multiple WSAs, repeat the following steps for each host.
Step 1
In the Advanced Web Security Reporting application: 
Choose Settings > Data > Data inputs > Files & directories
Step 2
Disable any inputs labeled 
CiscoWSA
Step 3
Click New.
Step 4
Click Continuously Monitor and provide the full path to the FTP directory to which WSA logs will be 
sent. 
This path and the FTP path provided on the WSA’s Log Subscription page must match. 
Step 5
Click Next.
Step 6
Click Manual as the Sourcetype and provide the Sourcetype label (
wsa_accesslogs
wsa_trafmonlogs
or 
wsa_amplogs
).
Step 7
Choose Advanced Web Security 5.0.0 from the App Context menu.
Step 8
Click Constant value and provide the WSA host name in the Host field value field.
Step 9
Choose Default as the destination Index.
Step 10
Click Review and review the values you provided.
Step 11
Click Submit.
Note
You can navigate to Settings > Data > Data inputs > Files & directories to confirm the new data 
input entry.
Configuration Of Data Input for WSA Syslogs
Step 1
In the Advanced Web Security Reporting application: 
Choose Settings > Data > Data inputs > TCP
Step 2
Click New.
Step 3
Click the TCP button and enter 
514
 in the Port field; leave the rest of the fields blank.
Step 4
Click Next.
Step 5
Click Manual and then enter 
wsa_syslog
 in the Sourcetype field.
Step 6
Choose Advanced Web Security 5.0.0 as the App Context.
Step 7
In the Host section, click Custom as the Method field, and then enter the WSA host name as the Host 
field value.
Step 8
Choose Default as the destination Index.
Step 9
Click Review and review the values you provided.
Step 10
Click Submit.