Troubleshoot Federated Search for Cisco Security Analytics and Logging
A list of issues you might encounter when setting up or using Cisco Security Analytics and Logging datasets.
The following table provides solutions for issues you might encounter when setting up Cisco Security Analytics and Logging (SAL) datasets, or when you run federated searches over those datasets
| Issue | Solution |
|---|---|
You encounter Cisco Security Analytics and Logging access token validation failures such as Authorization error. The provided token was already used. |
Cisco Security Analytics and Logging access tokens can fail validation for the following reasons:
For more information about generating access tokens and monitoring the connection between Cisco Security Analytics and Logging and the Splunk Cloud Platform, see Integration of Cisco Security Analytics and Logging with Splunk Federated Search in Security Cloud Control. |
You encounter conflict errors such as Dataset already exists. |
Splunk software displays an error message if your Cisco SAL access token connects to a Cisco SAL tenant that is already in use by an existing Cisco SAL dataset.
If the existing dataset for a Cisco SAL tenant is stale or incomplete, delete it, and set up a new dataset for that tenant. Apply a freshly generated Cisco SAL access token to the dataset to establish access to the data it represents. |
Your searches fail with the following error message: Dataset '<name_of_your_Cisco_SAL_dataset>' of kind 'cisco_sal' does not have the 'SEARCH' capability.. |
Federated search functionality is deactivated for the Cisco SAL dataset you are trying to use. To activate federated search functionality for the Cisco SAL dataset, go to the Datasets listing page or the Edit page for the dataset. See Manage a Cisco Security Analytics and Logging dataset. |
| Your federated search returns incomplete or no results. |
|