Platform: Splunk + Cisco Integrations

Community Office Hours

Platform: Splunk + Cisco Integrations

1 Comment
Cover Images - Office Hours (4).png
Published on ‎03-31-2025 12:03 PM by Splunk Employee | Updated on ‎05-27-2025 03:09 PM

Register here (watch on demand)This thread is for the Community Office Hours session on Splunk + Cisco Integrations on Thurs, May 22, 2025 at 1pm PT / 4pm ET

 

Ask the experts at Community Office Hours! An ongoing series where technical Splunk experts answer questions and provide how-to guidance on various Splunk product and use case topics.

 

What can I ask in this AMA?

  • What Splunk and Cisco integrations are available today?
  • What tools/TAs can I use to integrate my Splunk and Cisco data?
  • How can we ingest ASA, IOS, Meraki, or ThousandEyes data?
  • How can I view and analyze incidents within Splunk ES using Cisco XDR as a data source?
  • How do AppDynamics and Splunk Observability Cloud work together?
  • Anything else you’d like to learn!

 

Please submit your questions at registration. You can also head to the #office-hours user Slack channel to ask questions (request access here)

 

Pre-submitted questions will be prioritized. After that, we will open the floor up to live Q&A with meeting participants.

 

Look forward to connecting!



Labels (2)
0 Karma
adepp
Splunk Employee

Hi everyone! Here are a few questions from the session (get the full Q&A deck and live recording in the #office-hours Slack channel - request access here) :

 

Q1:What is the best pattern for syslog data from Cisco devices?

Q2: What is the best way to send data from Cisco switches/firewalls to Splunk?

Q3: How can I view and analyze incidents within Splunk ES using Cisco XDR as a data source? 

Other Questions (check the #office-hours Slack channel for responses):

  • Best practice for integration with Cisco products like FMC, FTD, AMP and Umbrella.
  • How to manage log ingestion made by fluent like we do with splunk universal forwarder and props
  • How will Splunk improve other Cisco security investments?
  • I have on-prem Enterprise 9.2. What are some ways to surface issues that should be checked by a network engineer?  Is there a way to surface data based on a delta from a baseline?  For example, if our network globally has some baseline amount of logs of type A, is there a way to alert when the amount of logs of that type change by +10% in a given time period?
  • How can I correlate what’s happening with my servers with what’s happening on my network?
  • Example of typical XDR alerts and how they show up in ES.  What other sources of data would correlate with these alerts?
  • OSINT / Threat intelligence ingestion
  • Dashboards for Cisco