All Apps and Add-ons

Cisco Networks App for Splunk Enterprise: Why am unable to view "Cisco_Device" lookup?

smitra_splunk
Splunk Employee
Splunk Employee

Hi,

I'm trying to get devices to show up under the Inventory -> Devices menu but nothing is displayed in the "software versions", "models", "mnemonics" panels. But there are plenty of IOS logs from routers and switches with sourcetype set to cisco:ios and eventtype cisco_ios.
Upon clicking a device IP on the Devices panel at the bottom of the page and new view opens up with a yellow triangle warning " The lookup table 'Cisco_Device' is invalid." There is nothing displayed on the entire Device view. Is this lookup supposed to exist or created manually ?

thanks,
Shreedeep Mitra.

0 Karma
1 Solution

mikaelbje
Motivator

Hi,

This feature requires Smart Call Home enabled on the devices and will only work on higher end devices. See the Help page in the app for info on setting this up.

I'm going to rip this feature out of the app since it's very flaky, so I suggest that you don't go down this road. You'll be better off getting this data from Cisco Prime Infrastructure or another NMS instead of relying on Smart Call Home.

Cheers,
Mikael

View solution in original post

mikaelbje
Motivator

Hi,

This feature requires Smart Call Home enabled on the devices and will only work on higher end devices. See the Help page in the app for info on setting this up.

I'm going to rip this feature out of the app since it's very flaky, so I suggest that you don't go down this road. You'll be better off getting this data from Cisco Prime Infrastructure or another NMS instead of relying on Smart Call Home.

Cheers,
Mikael

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...