All Apps and Add-ons

How to add the data of switches and routers into the Cisco Networks App for Splunk Enterprise?

splunkfly
New Member

How to configure adding the data of switches and routers into the Cisco Networks App for Splunk Enterprise?

0 Karma

gmerhej_splunk
Splunk Employee
Splunk Employee

Along with the App, you'll need to install the "Cisco Networks Add-on" and to use the sourcetype cisco:ios for the Syslog data sent from the switches and routers.

0 Karma

splunkfly
New Member

I have logs data stored on Syslog-ng ---->universal forwarder----> splunk Server
I couldn't find the feature sourcetype cisco:ios for the Syslog data sent from the switches and routers.
The Networks App looks great but I Need input the data from syslog server to splunk app, that's the challenging. If you can be help me with bit more information would helps me a lot.

0 Karma

gmerhej_splunk
Splunk Employee
Splunk Employee

You will need to manually define the sourcetype in the inputs.conf under the monitor stanza:

http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/Bypassautomaticsourcetypeassignment

0 Karma

splunkfly
New Member

is this path is correct where inputs.conf file located ?? (Splunk_Home/etc/system/local/inputs.conf)

0 Karma

gmerhej_splunk
Splunk Employee
Splunk Employee

There are many inputs.conf. However, it's better to do the configuration in Splunk_Home/etc/apps/search/local/inputs.conf

0 Karma
Get Updates on the Splunk Community!

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...