Getting Data In

Adding cisco switches, (all kinds), to syslog to Splunk

rmcole
New Member

I've tried adding a new UDP data input but it feels like something is missing. I went as far as to cause events on a switch that should normally be sent to a syslog server (Splunk in this case). I am very new to the management side of Splunk so please speak simple.

Ok, I give up. Splunk is one of 1000 things I do and I'm tired of wasting time messing with it.
There's got to be something better out there!

Tags (1)
0 Karma
1 Solution

dshpritz
SplunkTrust
SplunkTrust

If the events are showing up in Splunk, then your next step is to get some field extractions for the data. You're in luck, there is a Technology Add-on for Cisco IOS, which should get you a pretty good start. Then start exploring your data.

View solution in original post

dshpritz
SplunkTrust
SplunkTrust

If the events are showing up in Splunk, then your next step is to get some field extractions for the data. You're in luck, there is a Technology Add-on for Cisco IOS, which should get you a pretty good start. Then start exploring your data.

dshpritz
SplunkTrust
SplunkTrust

Have you looked at the docs on field extractions? http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsatsearchtime

The TA that I linked to should provide some out of the box extractions, but it would also depend on what the sourcetype of your incoming data is. Is the data currently sourcetyped as syslog?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...