All Apps and Add-ons

I am not seeing results in dashboards for cisco networks. Do we need to configure something on router/n/w devices?

yanivdutt
Explorer

index=network_syslog sourcetype=syslog results are displayed

index=network_syslog sourcetype=syslog eventtype="cisco_ios-ipsla" | eval state=case(state_to == "Up", 1, state_to == "Down", -1) | strcat dvc " " ip_sla_id dvc_ip_sla_id | timechart avg(state) AS state BY dvc_ip_sla_id | fillnull value=0    no results founds

Do we need to configure anything on routers or network devices?

0 Karma
1 Solution

Simeon
Splunk Employee
Splunk Employee

To begin collecting data from Cisco devices, you must minimally enable a network input to receive data and configure the cisco device to send syslog to the Splunk instance (or forwarder). If you are using the Cisco Security Suite, there are detailed instructions on how to turn on data for the Cisco devices in addition to enabling Splunk to receive and recognize the data.

View solution in original post

Simeon
Splunk Employee
Splunk Employee

To begin collecting data from Cisco devices, you must minimally enable a network input to receive data and configure the cisco device to send syslog to the Splunk instance (or forwarder). If you are using the Cisco Security Suite, there are detailed instructions on how to turn on data for the Cisco devices in addition to enabling Splunk to receive and recognize the data.

Richfez
SplunkTrust
SplunkTrust

If you run index=network_syslog sourcetype=syslog can you confirm that "eventtype" is indeed being set and that at least some of them are set to "cisco_ios-ipsla"?

0 Karma

yanivdutt
Explorer

Nope I dont see any events with cisco_ios*
I was asked to install cisco add on app on indexers which I am yet to do. Will keep you posted if results are changed after doing it

0 Karma

satishsdange
Builder
0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...
OSZAR »