Archive
Highlighted

How to configure "Cisco Networks Add-on for Splunk Enterprise"

Explorer

I have installed "Cisco Networks Add-on for Splunk Enterprise" on my splunk enterprise server.
I able to get the data from cisco device on UDP:514 with sourcetype=cisco:ios.
Please help me how to configure this app produce dashboard of that data on this app. Does this app have any default dashboards/reports.

Am not sure if my configuration is wrong or this app/addon itself doesn't have any prebuilt dashboard/reports.

@mikaelbje

Pls help/calrify.

~CKP

Tags (1)
0 Karma
Highlighted

Re: How to configure "Cisco Networks Add-on for Splunk Enterprise"

Motivator

You need the App as well, not just the add-on.
This is mentioned in the documentation 🙂

0 Karma
Highlighted

Re: How to configure "Cisco Networks Add-on for Splunk Enterprise"

Explorer

App is also there. Attaching the snap for your reference. Am I missing any others step apart from mentioned steps.

0 Karma
Highlighted

Re: How to configure "Cisco Networks Add-on for Splunk Enterprise"

Explorer

alt text

App is also there. Attaching the snap for your reference. Am I missing any others step apart from mentioned steps.

View solution in original post

0 Karma
Highlighted

Re: How to configure "Cisco Networks Add-on for Splunk Enterprise"

Motivator

The app name looks very strange. Are you sure you installed it correctly? If it was installed correctly you should get to an overview page with a summary of the events from your Cisco network infrastructure. Have a look in the Splunk app install folder under etc/apps and check if anything looks strange compared to other apps

0 Karma
Highlighted

Re: How to configure "Cisco Networks Add-on for Splunk Enterprise"

Motivator

Also the add-on should not be visible in that drop-down. Looks like someone has changed the contents of the app and add-on in some way.

0 Karma
Highlighted

Re: How to configure "Cisco Networks Add-on for Splunk Enterprise"

Explorer

Yes.. There was some configuration issue when upload on web. Unzipped and copied to apps directory manually and it worked like a charm. I have kept source type as cisco:ios.

0 Karma
Highlighted

Re: How to configure "Cisco Networks Add-on for Splunk Enterprise"

Communicator

The Cisco Networks Add-on (TA-cisco_ios) does not need any special configuration setup. You only need to set the correct source types i.e. cisco:ios for networking devices, such as routers and switches and WLC. The Cisco Networks App for Splunk Enterprise also does not require much of setup.

The Cisco Networks App for Splunk Enterprise comes with few pre-built dashboards and reports. You only need to make sure the data is indexed correctly with the correct source type and the user has correct permissions.

I am noting a few points that you can check :

  1. The source type for the input is correct.
  2. If you are using any custom index other than main, does the user has access to that index? You can go to Settings>> Access Controls >> Roles >> 'select role' >> Indexes searched by default.
  3. Please make sure, the searches behind the dashboard are producing results.
  4. Make sure that data is received and indexed in splunk by doing a search on the sourcetype.

Hope this Helps.

0 Karma