<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring Splunk with SIP messaging for troubleshooting in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Configuring-Splunk-with-SIP-messaging-for-troubleshooting/m-p/152169#M9807</link>
    <description>&lt;P&gt;Have you created a sourcetype for this data type?  You would likely need to do this at the forwarder (props), break on time or use MAX_TIMESTAMP_LOOKAHEAD.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 07:19:33 GMT</pubDate>
    <dc:creator>3stimpson</dc:creator>
    <dc:date>2020-09-29T07:19:33Z</dc:date>
    <item>
      <title>Configuring Splunk with SIP messaging for troubleshooting</title>
      <link>https://community.splunk.com/t5/Installation/Configuring-Splunk-with-SIP-messaging-for-troubleshooting/m-p/152168#M9806</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;

&lt;P&gt;We have logging enabled for our SIP Cisco UBE SBC and Splunk.  &lt;/P&gt;

&lt;P&gt;The data is available in Splunk at this moment in time although we will be using this data for troubleshooting purposes and the data gets manipulated in a way which makes it hard to read and understand. &lt;/P&gt;

&lt;P&gt;Is there a way to keep the formatting the same? .ie from extracting from splunk you can see the latest date/time is on the top, also splunk has added date time and also changed the format.&lt;/P&gt;

&lt;P&gt;An example below (extracted for Splunk:&lt;/P&gt;

&lt;P&gt;Nov 25 14:10:59 10.90.0.11 147443: Received: &lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147442: 570654: Nov 25 14:10:59.413: //-1/xxxxxxxxxxxx/SIP/Msg/ccsipDisplayMsg:&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147441: a=ptime:20&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147440: a=fmtp:101 0-15&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147439: a=rtpmap:101 telephone-event/8000&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147438: a=rtpmap:8 PCMA/8000&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147437: c=IN IP4 10.239.194.122&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147436: m=audio 32532 RTP/AVP 8 101&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147435: t=0 0&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147434: c=IN IP4 10.239.194.122&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147433: s=SIP Call&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147432: o=CiscoSystemsSIP-GW-UserAgent 4029 7840 IN IP4 10.239.194.122&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147431: v=0&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147430: &lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147429: Content-Length: 253&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147428: Content-Disposition: session;handling=required&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147427: Content-Type: application/sdp&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147426: Supported: timer&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147425: Server: Cisco-SIPGateway/IOS-15.2.4.M4&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147424: Supported: sdp-anat&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147423: Supported: replaces&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147422: Contact: &lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147421: Allow-Events: telephone-event&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147420: STER&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147419: Allow: INVITE, OPTIONS, BYE, CANCEL, ACK, PRACK, UPDATE, REFER, SUBSCRIBE, NOTIFY, INFO, REGI&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147418: CSeq: 73687 INVITE&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147417: Call-ID: &lt;A href="mailto:9de3ee4e94d72128745feecb7745fc2f550e5ac2@210.87.44.134"&gt;9de3ee4e94d72128745feecb7745fc2f550e5ac2@210.87.44.134&lt;/A&gt;&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147416: Date: Tue, 25 Nov 2014 03:10:59 GMT&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147415: To: ;tag=9E38E484-23F&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147414: From: "0269772016";tag=22272&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147413: Via: SIP/2.0/UDP 202.10.4.169:5060;branch=z9hG4bK36dddh301oog75ji75l0.1&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147412: SIP/2.0 200 OK&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147411: Sent: &lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147410: 570653: Nov 25 14:10:59.385: //271697/839062628307/SIP/Msg/ccsipDisplayMsg:&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147409: &lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147408: Content-Length: 0&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147407: Allow-Events: telephone-event&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147406: CSeq: 101 ACK&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147405: Max-Forwards: 70&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147404: Call-ID: &lt;A href="mailto:8390FE8A-738711E4-830DB48F-F8E6D51B@sipvoice.syd.aapt.com.au"&gt;8390FE8A-738711E4-830DB48F-F8E6D51B@sipvoice.syd.aapt.com.au&lt;/A&gt;&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147403: Date: Tue, 25 Nov 2014 03:10:59 GMT&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147402: To: ;tag=5067052~03b5356b-9a57-45a8-bade-5339176b91af-112479176&lt;BR /&gt;
Nov 25 14:10:59 10.90.0.11 147401: From: "0269772016" &lt;/P&gt;

&lt;P&gt;Extracted from logging on Cisco UBE:&lt;/P&gt;

&lt;P&gt;5MRL1-G1#&lt;BR /&gt;
000164: Oct 29 13:25:59.454: //-1/xxxxxxxxxxxx/SIP/Msg/ccsipDisplayMsg:&lt;BR /&gt;
Received: &lt;BR /&gt;
INVITE sip:&lt;A href="mailto:0395468066@10.90.0.10"&gt;0395468066@10.90.0.10&lt;/A&gt;:5060 SIP/2.0&lt;BR /&gt;
Via: SIP/2.0/UDP 10.90.208.22:5060;branch=z9hG4bK4dc8cd5de53bd6&lt;BR /&gt;
From: ;tag=45330452~03b5356b-9a57-45a8-bade-5339176b91af-110953498&lt;BR /&gt;
To: ;tag=1306D250-BA5&lt;BR /&gt;
Date: Wed, 29 Oct 2014 02:25:59 GMT&lt;BR /&gt;
Call-ID: &lt;A href="mailto:B2BD56C0-5E4911E4-B935B48F-F8E6D51B@sipvoice.syd.aapt.com.au"&gt;B2BD56C0-5E4911E4-B935B48F-F8E6D51B@sipvoice.syd.aapt.com.au&lt;/A&gt;&lt;BR /&gt;
Supported: timer,resource-priority,replaces&lt;BR /&gt;
Min-SE:  1800&lt;BR /&gt;
Cisco-Guid: 2998712831-1581847012-3106911375-4175877403&lt;BR /&gt;
User-Agent: Cisco-CUCM8.6&lt;BR /&gt;
Allow: INVITE, OPTIONS, INFO, BYE, CANCEL, ACK, PRACK, UPDATE, REFER, SUBSCRIBE, NOTIFY&lt;BR /&gt;
CSeq: 101 INVITE&lt;BR /&gt;
Max-Forwards: 70&lt;BR /&gt;
Expires: 180&lt;BR /&gt;
Allow-Events: presence, kpml&lt;BR /&gt;
Call-Info: ;method="NOTIFY;Event=telephone-event;Duration=500"&lt;BR /&gt;
Supported: X-cisco-srtp-fallback&lt;BR /&gt;
Supported: Geolocation&lt;BR /&gt;
Session-Expires:  1800;refresher=uac&lt;BR /&gt;
P-Asserted-Identity: &lt;BR /&gt;
Remote-Party-ID: ;party=calling;screen=yes;privacy=off&lt;BR /&gt;
Contact: &lt;BR /&gt;
Content-Type: application/sdp&lt;BR /&gt;
Content-Length: 246&lt;/P&gt;

&lt;P&gt;v=0&lt;BR /&gt;
o=CiscoSystemsCCM-SIP 45330452 2 IN IP4 10.90.208.22&lt;BR /&gt;
s=SIP Call&lt;BR /&gt;
c=IN IP4 0.0.0.0&lt;BR /&gt;
b=TIAS:64000&lt;BR /&gt;
b=AS:64&lt;BR /&gt;
t=0 0&lt;BR /&gt;
m=audio 31358 RTP/AVP 8 101&lt;BR /&gt;
a=rtpmap:8 PCMA/8000&lt;BR /&gt;
a=ptime:20&lt;BR /&gt;
a=inactive&lt;BR /&gt;
a=rtpmap:101 telephone-event/8000&lt;BR /&gt;
a=fmtp:101 0-15&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2014 04:17:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Configuring-Splunk-with-SIP-messaging-for-troubleshooting/m-p/152168#M9806</guid>
      <dc:creator>vitkop1</dc:creator>
      <dc:date>2014-12-17T04:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Splunk with SIP messaging for troubleshooting</title>
      <link>https://community.splunk.com/t5/Installation/Configuring-Splunk-with-SIP-messaging-for-troubleshooting/m-p/152169#M9807</link>
      <description>&lt;P&gt;Have you created a sourcetype for this data type?  You would likely need to do this at the forwarder (props), break on time or use MAX_TIMESTAMP_LOOKAHEAD.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:19:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Configuring-Splunk-with-SIP-messaging-for-troubleshooting/m-p/152169#M9807</guid>
      <dc:creator>3stimpson</dc:creator>
      <dc:date>2020-09-29T07:19:33Z</dc:date>
    </item>
  </channel>
</rss>

