All Apps and Add-ons

How to add the data of switches and routers into the Cisco Networks App for Splunk Enterprise?

splunkfly
New Member

How to configure adding the data of switches and routers into the Cisco Networks App for Splunk Enterprise?

0 Karma

gmerhej_splunk
Splunk Employee
Splunk Employee

Along with the App, you'll need to install the "Cisco Networks Add-on" and to use the sourcetype cisco:ios for the Syslog data sent from the switches and routers.

0 Karma

splunkfly
New Member

I have logs data stored on Syslog-ng ---->universal forwarder----> splunk Server
I couldn't find the feature sourcetype cisco:ios for the Syslog data sent from the switches and routers.
The Networks App looks great but I Need input the data from syslog server to splunk app, that's the challenging. If you can be help me with bit more information would helps me a lot.

0 Karma

gmerhej_splunk
Splunk Employee
Splunk Employee

You will need to manually define the sourcetype in the inputs.conf under the monitor stanza:

http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/Bypassautomaticsourcetypeassignment

0 Karma

splunkfly
New Member

is this path is correct where inputs.conf file located ?? (Splunk_Home/etc/system/local/inputs.conf)

0 Karma

gmerhej_splunk
Splunk Employee
Splunk Employee

There are many inputs.conf. However, it's better to do the configuration in Splunk_Home/etc/apps/search/local/inputs.conf

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...