Maybe someone can help me with this. I followed the instructions and changed my sourcetype to syslog since I do not have any sourcetype built for cisco:ios. I have yet to see any data even though I have tons of data coming in. Can anyone please help me figure out what I'm currently doing wrong?
Any and all help is appreciated
It started to pick up information in the sourcetype=cisco:ios. I think I figured out the issue. I thought that there was no add-on due to only reading the title. I have added the add-on and that fixed it. Thanks for responding to me so quickly Mike.
It looks like it started to pull data after I restarted the splunk search head. It apparently only see's port flappings but not unique devices and other issues that are probably being reported by my cisco devices.