We are trying to allow the Splunk Add-on for Cisco UCS to connect to our UCS manager, but we are not sure which protocol is used and we have a firewall between them.
So far, all we get are ERROR Response not ready in /opt/splunk/var/log/splunk/ta_cisco_ucs.log
Thanks
Thomas
The Splunk Add-on for Cisco UCS collects data and interacts with UCS Manager via the UCS XML API which is web-based (HTTP or HTTPS). Therefore, any firewall between Splunk and UCS Manager should be configured to allow all web traffic over the standard HTTP(TCP/80) or HTTPS(TCP/443) or any custom ports if configured (check with your UCS admin).
Can you confirm if the UCS API for your UCS manager is configured with a custom port other than the defaults (TCP/80 or TCP/443) ?
Our Cisco UCS manager was using the defaults ports. We managed to connect to it by opening the HTTPS traffic between these hosts.
Thanks
Thomas