<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Switch Data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Switch-Data/m-p/579506#M102300</link>
    <description>&lt;P&gt;Sending syslog directly to Splunk is discouraged.&amp;nbsp; Best Practice is to have the syslog server write the data to disk files and have Splunk monitor those files.&amp;nbsp; Another option is to use the Splunk Connect for Syslog (SC4S) app.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Dec 2021 17:53:45 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-12-29T17:53:45Z</dc:date>
    <item>
      <title>Cisco Switch Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Switch-Data/m-p/579464#M102295</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have multiple Cisco Switches that are configured to send logs to Splunk.&amp;nbsp; When comparing the logs on the switch and the logs in Splunk, they do not match up.&amp;nbsp; Splunk does not seem to catch all of the logs, and seems to miss entries in large chunks, and it does not seem to be any single type of entry.&amp;nbsp; &amp;nbsp;I've searched by the IP of the switch and the information in the log thinking that it might have been mislabeled, but it is not in Splunk at all.&lt;/P&gt;&lt;P&gt;We have our switches set up to log at an informational level.&amp;nbsp; This is happening across most switches in our environments - not all logs are entering Splunk.&amp;nbsp; &amp;nbsp;Is this is a known issue?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 13:18:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Switch-Data/m-p/579464#M102295</guid>
      <dc:creator>mcrist3</dc:creator>
      <dc:date>2021-12-29T13:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Switch-Data/m-p/579488#M102298</link>
      <description>&lt;P&gt;How does the data get from the switches to Splunk?&amp;nbsp; Are they sent via syslog?&amp;nbsp; Do the events go directly to Splunk or to a syslog server?&amp;nbsp; Are the sent using TCP or UDP?&amp;nbsp; Some configurations are more likely to lead to data loss than others.&lt;/P&gt;&lt;P&gt;Another possibility is the data is getting to Splunk, but is onboarded poorly so events cannot be located.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 15:14:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Switch-Data/m-p/579488#M102298</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-12-29T15:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Switch-Data/m-p/579495#M102299</link>
      <description>&lt;P&gt;We have the switches configured to send via Kiwi syslog - the syslog server is also installed on the Splunk server.&amp;nbsp; We have the Data Inputs in Splunk listening on 514 TCP and UDP, with a source type of syslog.&amp;nbsp; TCP is also listening on 601 with a source type of cisco_syslog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The switch shows (show logging command):&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;/P&gt;&lt;P&gt;Trap Logging Informational, 245 message lines logged&lt;/P&gt;&lt;P&gt;Logging to &amp;lt;Splunk/KiwiIP&amp;gt; (udp port 514, audit disabled, link up)&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;Logging to &amp;lt;Splunk/KiwiIP&amp;gt; (tcp port 601, audit disabled, link up)&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 15:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Switch-Data/m-p/579495#M102299</guid>
      <dc:creator>mcrist3</dc:creator>
      <dc:date>2021-12-29T15:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Switch-Data/m-p/579506#M102300</link>
      <description>&lt;P&gt;Sending syslog directly to Splunk is discouraged.&amp;nbsp; Best Practice is to have the syslog server write the data to disk files and have Splunk monitor those files.&amp;nbsp; Another option is to use the Splunk Connect for Syslog (SC4S) app.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 17:53:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Switch-Data/m-p/579506#M102300</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-12-29T17:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch Data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-Switch-Data/m-p/579507#M102301</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp; I will take a look at our set up and see if we can get this updated.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 17:59:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-Switch-Data/m-p/579507#M102301</guid>
      <dc:creator>mcrist3</dc:creator>
      <dc:date>2021-12-29T17:59:10Z</dc:date>
    </item>
  </channel>
</rss>

