All Apps and Add-ons

How to add the data of switches and routers into the Cisco Networks App for Splunk Enterprise?

splunkfly
New Member

How to configure adding the data of switches and routers into the Cisco Networks App for Splunk Enterprise?

0 Karma

gmerhej_splunk
Splunk Employee
Splunk Employee

Along with the App, you'll need to install the "Cisco Networks Add-on" and to use the sourcetype cisco:ios for the Syslog data sent from the switches and routers.

0 Karma

splunkfly
New Member

I have logs data stored on Syslog-ng ---->universal forwarder----> splunk Server
I couldn't find the feature sourcetype cisco:ios for the Syslog data sent from the switches and routers.
The Networks App looks great but I Need input the data from syslog server to splunk app, that's the challenging. If you can be help me with bit more information would helps me a lot.

0 Karma

gmerhej_splunk
Splunk Employee
Splunk Employee

You will need to manually define the sourcetype in the inputs.conf under the monitor stanza:

http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/Bypassautomaticsourcetypeassignment

0 Karma

splunkfly
New Member

is this path is correct where inputs.conf file located ?? (Splunk_Home/etc/system/local/inputs.conf)

0 Karma

gmerhej_splunk
Splunk Employee
Splunk Employee

There are many inputs.conf. However, it's better to do the configuration in Splunk_Home/etc/apps/search/local/inputs.conf

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...