All Apps and Add-ons

Cisco IOS app: Why aren't any data or devices displayed?

vitasliu
New Member

hi, i have installed the cisco ios app and TA-cisco_ios on the index server and search server. Now i can receive some messages in the search head come from switch just like "Aug 18 20:39:51 172.16.50.254 222176: Aug 18 20:39:49: %MAC_MOVE-SW1_SP-4-NOTIF: Host f8bc.123b.5e74 in vlan 23 is flapping between port Po85 and port Po84", but the cisco ios app doesn't see any content to display. My index server and search server is splunk 6.0. Is there anything wrong with my configuration?

0 Karma
1 Solution

mikaelbje
Motivator

Hi,

The latest version of the app relies heavily on the latest features of Splunk Data Models and requires Splunk 6.1 to show data in the initial overview page as well as a few other views. I'd suggest that you upgrade your search head to Splunk 6.1.3 and see if that helps.

Please rate my answer if it was helpful.

Regards,

Mikael

View solution in original post

0 Karma

mikaelbje
Motivator

Hi,

The latest version of the app relies heavily on the latest features of Splunk Data Models and requires Splunk 6.1 to show data in the initial overview page as well as a few other views. I'd suggest that you upgrade your search head to Splunk 6.1.3 and see if that helps.

Please rate my answer if it was helpful.

Regards,

Mikael

0 Karma

mikaelbje
Motivator

I found the error!

I had an extraction for MACFLAP_NOTIF, but not for NOTIF. I fixed this up and also added mnemonic=NOTIF to the eventtype. Since a lot of the logging events vary between platforms it's hard to get correct extractions for all cases.

You can download the latest development version of TA-cisco_ios here:

https://github.com/inspired/TA-cisco_ios

0 Karma

vitasliu
New Member

of course ,it shows full thing on event atcions that when use search index=* sourcetype=cisco:ios just like severity=medium vendor vendor_recommended action,facility=MAC-MOVE

0 Karma

mikaelbje
Motivator

Hmm, so when you search for index=* sourcetype=cisco:ios that particular event isn't shown?

0 Karma

vitasliu
New Member

but mac flapping module still does't display any date when i use last 24hours to search ,i'm sure my switch last day send many flapping messages to splunk server just like "Aug 18 20:39:51 172.16.50.254 222176: Aug 18 20:39:49: %MAC_MOVE-SW1_SP-4-NOTIF: Host f8bc.123b.5e74 in vlan 23 is flapping between port Po85 and port Po84". is there anything i need to notice ?

0 Karma

vitasliu
New Member

thanks, after upgrade ,it see something in the apps.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...