cisco-secure-email-web-gateway-setup

Community

Unified Cisco ESA/WSA setup in Splunk

Authorchambear2809
Version1.0.0
Installs0

System Documentation

What problem does it solve?

Install, configure, and validate the Splunk-supported Cisco ESA and WSA add-ons. Covers ESA/WSA indexes, macros, parser placement, SC4S/file-monitor ingestion handoffs, source/sourcetype coverage, and CIM validation. Use when the user asks about Cisco Secure Email Gateway, ESA, WSA, IronPort, email security, web security, or Cisco ESA/WSA Splunk add-ons.

Core Features & Use Cases

  • ESA/WSA Add-on Setup: Install and configure the Splunk Add-ons for Cisco ESA and Cisco WSA.
  • Index, Macro, and Ingestion Handoff: Create and align the necessary indexes, macros, and SC4S/file-monitor handoffs to ensure CIM-aligned data ingestion.
  • Validation & Readiness: Validate CIM alignment and verify dashboards/macros are available and functional.

Quick Start

Run the setup script to install ESA/WSA add-ons and validate readiness.

Dependency Matrix

Required Modules

None required

Components

scriptsreferences

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: cisco-secure-email-web-gateway-setup
Download link: https://github.com/chambear2809/splunk-cisco-skills/archive/main.zip#cisco-secure-email-web-gateway-setup

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 510,000+ vetted skills library on demand.