Troubleshoot Federated Search for Cisco Security Analytics and Logging

A list of issues you might encounter when setting up or using Cisco Security Analytics and Logging datasets.

The following table provides solutions for issues you might encounter when setting up Cisco Security Analytics and Logging (SAL) datasets, or when you run federated searches over those datasets

Issue Solution
You encounter Cisco Security Analytics and Logging access token validation failures such as Authorization error. The provided token was already used. Cisco Security Analytics and Logging access tokens can fail validation for the following reasons:
  • Your access token is invalid or has expired. Cisco SAL access tokens are single-use. Get a fresh token from the Cisco SAL administrator and try again.

  • The token provides access to a Cisco SAL tenant that resides in a different AWS region from your Splunk Cloud Platform deployment. If this is the case, obtain an access token for a Cisco SAL tenant that is in the same AWS location as your Splunk Cloud Platform deployment.

  • The connection between Cisco Security Analytics and Logging and your Splunk Cloud Platform deployment is disconnected. Reach out to the Cisco SAL administrator and have them restore the connection in Cisco Security Cloud Control.

For more information about generating access tokens and monitoring the connection between Cisco Security Analytics and Logging and the Splunk Cloud Platform, see Integration of Cisco Security Analytics and Logging with Splunk Federated Search in Security Cloud Control.

You encounter conflict errors such as Dataset already exists. Splunk software displays an error message if your Cisco SAL access token connects to a Cisco SAL tenant that is already in use by an existing Cisco SAL dataset.

If the existing dataset for a Cisco SAL tenant is stale or incomplete, delete it, and set up a new dataset for that tenant. Apply a freshly generated Cisco SAL access token to the dataset to establish access to the data it represents.

Your searches fail with the following error message: Dataset '<name_of_your_Cisco_SAL_dataset>' of kind 'cisco_sal' does not have the 'SEARCH' capability.. Federated search functionality is deactivated for the Cisco SAL dataset you are trying to use. To activate federated search functionality for the Cisco SAL dataset, go to the Datasets listing page or the Edit page for the dataset. See Manage a Cisco Security Analytics and Logging dataset.
Your federated search returns incomplete or no results.
  • If the default 30 minute time range does not return data, rerun the search over a longer time range based on your Cisco SAL data availability to retrieve results.

  • If expanding the range doesn't work, your Cisco SAL dataset might not have any data available for federated searches. Contact the Cisco SAL administrator and have them verify whether firewall events are flowing into the Events and Logs page in the Security Cloud Control platform. See Integration of Cisco Security Analytics and Logging with Splunk Federated Search in Security Cloud Control.