All Apps and Add-ons

Cisco app not showing any data but receiving logs

haleyh44
Path Finder

The cisco app shows no data from the syslog but if i run a search my network devices are sending syslogs to the correct indexer. 

UDP:514 - cisco:ios

My splunk infrastructure is just a single server preforming all functions.

 

Please give me some suggestions to troubleshoot! I have tried deleting the data inputs are readding but with no luck.

Labels (1)
0 Karma
1 Solution

haleyh44
Path Finder

I re-downloaded the TA_cisco-ios add on and it finally started working! I think the one i downloaded to install offline may have not gotten all the files needed. 

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Make sure the Cisco IOS TA is installed and enabled.  If it is, go to Settings->Event types and make sure the eventtype itself is enabled.

---
If this reply helps you, Karma would be appreciated.
0 Karma

haleyh44
Path Finder

I re-downloaded the TA_cisco-ios add on and it finally started working! I think the one i downloaded to install offline may have not gotten all the files needed. 

0 Karma

haleyh44
Path Finder

So i just tried to search for the eventtype cisco_ios and its telling me it does not exist or is disabled? Any suggestions on how i get that eventype enabled?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Apparently, the Cisco app is not performing the same search you are performing manually.  Examine the searches the app uses (click the magnifying glass icon on a panel or use the CLI to view the dashboard code) and compare it to your manual search.  Based on your findings, adjust how the data is onboarded or modify the queries.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...