All Apps and Add-ons

How to add Cisco devices to the Cisco Networks App for Splunk Enterprise?

New Member

I have Cisco logs coming into my syslog-ng server, and I added the log file on a universal forwarder to monitor and send to a Splunk server. How do I check whether or not data is being dumped into the indexer? I also want to add Cisco devices to the Cisco Networks App in Splunk. How do I do this?

0 Karma

Motivator

The TA is required on the HF if that is where your syslog is coming in.

You do not need an inputs.conf on the indexers, only on your forwarder.

0 Karma

Path Finder

In my case there was no act of "adding devices" -- they just showed up as soon as data started flowing into the indexer and by show up I mean I was able to see them under Cisco Networks App for Splunk Enterprise. The thing was that I initially used snmp traps and NONE showed up. I figured later that I must use syslog but then the substance which syslog provides doesn't give me what I want to I was back to square one with my logs. In summary, if nothing shows up under Cisco Networks App for Splunk Enterprise then data isn't making it to the indexer. There isn't any manual task inside Cisco Networks App for Splunk Enterprise to add devices, as far as my knowledge goes.

0 Karma

Motivator

Correct, for most Splunk apps there is no need to add sending devices. Splunk works on whatever data is being received.

0 Karma

Explorer

Mikalbje,

I am having an issue, I am working with someone who has the Cisco Network Add-on for Splunk installed in the Syslog server, but not their Heavy Forwarder, also I see that the Cluster Master has the app and due to it, it was deployed to all four indexers as well. The TA and Cisco Network app is also installed on their utility search head, but I am not seeing any data. I see that the syslog installation of the TA has an inputs.conf file in the app/local folder, but none exists on the indexers because there is no configuration on the cluster master. Does there need to be any inputs.conf file in the app/local or not? Also should I install the TA on the HF as well?

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!