<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to view Nexus data in main dashboard of Cisco Networks App in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-view-Nexus-data-in-main-dashboard-of-Cisco-Networks/m-p/371401#M67420</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;since the post is awaiting moderation I have to post this as a comment, not an answer. Feel free to change this to an answer and accept.&lt;/P&gt;

&lt;P&gt;You need to set the sourcetype of your data to "cisco:ios" OR "syslog". You will also need the Cisco Networks Add-on on your indexers and search head as described in the documentation.&lt;/P&gt;

&lt;P&gt;"cisco:ios" is faster since Splunk won't need to rewrite the sourcetype based on a transform. Consider "syslog" a last resort.&lt;/P&gt;

&lt;P&gt;As soon as this is corrected you will see your data in the Cisco Networks app. If you still don't see data you will need to make whatever index the data is stored in searched by default. This is done in Access Controls -&amp;gt; Roles in Splunk&lt;/P&gt;</description>
    <pubDate>Thu, 23 Mar 2017 10:34:20 GMT</pubDate>
    <dc:creator>mikaelbje</dc:creator>
    <dc:date>2017-03-23T10:34:20Z</dc:date>
    <item>
      <title>Unable to view Nexus data in main dashboard of Cisco Networks App</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-view-Nexus-data-in-main-dashboard-of-Cisco-Networks/m-p/371400#M67419</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2666i0C4697F5150AA57C/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Hi there, &lt;/P&gt;

&lt;P&gt;I've just recently installed the 'Cisco Networks' app &lt;A href="https://splunkbase.splunk.com/app/1352/"&gt;https://splunkbase.splunk.com/app/1352/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;However in the main dashboard or 'cisco networks overview' for product there is only an option for ios, wlc, ap. In the switching tab/dashboard there doesn't seem to be anything displayed for the nexus switches. &lt;/P&gt;

&lt;P&gt;The only way I can see data from the nexus switch is in 'search' (attached) via an IP address&lt;/P&gt;

&lt;P&gt;In the data input section in settings, I've put in the UDP port it would be received on, and the source type as 'cisco_syslog' as there didn't seem to be an option for nx-os or nexus.&lt;/P&gt;

&lt;P&gt;Have I  missed out a setting/configuration?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Shams&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 09:38:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-view-Nexus-data-in-main-dashboard-of-Cisco-Networks/m-p/371400#M67419</guid>
      <dc:creator>shamscw</dc:creator>
      <dc:date>2017-03-23T09:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view Nexus data in main dashboard of Cisco Networks App</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-view-Nexus-data-in-main-dashboard-of-Cisco-Networks/m-p/371401#M67420</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;since the post is awaiting moderation I have to post this as a comment, not an answer. Feel free to change this to an answer and accept.&lt;/P&gt;

&lt;P&gt;You need to set the sourcetype of your data to "cisco:ios" OR "syslog". You will also need the Cisco Networks Add-on on your indexers and search head as described in the documentation.&lt;/P&gt;

&lt;P&gt;"cisco:ios" is faster since Splunk won't need to rewrite the sourcetype based on a transform. Consider "syslog" a last resort.&lt;/P&gt;

&lt;P&gt;As soon as this is corrected you will see your data in the Cisco Networks app. If you still don't see data you will need to make whatever index the data is stored in searched by default. This is done in Access Controls -&amp;gt; Roles in Splunk&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 10:34:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-view-Nexus-data-in-main-dashboard-of-Cisco-Networks/m-p/371401#M67420</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2017-03-23T10:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view Nexus data in main dashboard of Cisco Networks App</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-view-Nexus-data-in-main-dashboard-of-Cisco-Networks/m-p/371402#M67421</link>
      <description>&lt;P&gt;Excellent thanks! that works! I got the 'add-on' and change the source type and now I can see events in the main dashboard. Thankyou&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 12:06:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-view-Nexus-data-in-main-dashboard-of-Cisco-Networks/m-p/371402#M67421</guid>
      <dc:creator>shamscw</dc:creator>
      <dc:date>2017-03-23T12:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view Nexus data in main dashboard of Cisco Networks App</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-view-Nexus-data-in-main-dashboard-of-Cisco-Networks/m-p/371403#M67422</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
we have the same issue and our Splunk admin followed the rules &lt;BR /&gt;
but nevertheless all is seen as cisco:ios no difference for ios-xe or nx-os&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    splunk@xxx % tail -5 props.conf
    [CC:syslog]
    TRANSFORMS-force_sourcetypes_cc = force_sourcetype_cisco_asa, force_sourcetype_for_cisco_ios, force_sourcetype_for_cisco_ios-xr, force_sourcetype_for_cisco_ios-xe
    SHOULD_LINEMERGE = false
    KV_MODE = none
    TZ = UTC
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So any clue what's wrong ?&lt;BR /&gt;
We had also updated App and Add-on to 2.5.8 &lt;/P&gt;

&lt;P&gt;Do I have to ask a new question or does this still fit to this post ?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 14:12:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-view-Nexus-data-in-main-dashboard-of-Cisco-Networks/m-p/371403#M67422</guid>
      <dc:creator>maikhahn</dc:creator>
      <dc:date>2019-07-03T14:12:20Z</dc:date>
    </item>
  </channel>
</rss>

