Getting Data In

How do I get data from my Cisco switch into Splunk?

jasonpoth
New Member

I am new to Splunk. I have set it up on my server, set up an indexer, and set up the logging in my switch, but I have no data. I do not see the option for Cisco:ios. How do you install the technology plugin?

0 Karma

shaskell_splunk
Splunk Employee
Splunk Employee

The best practice is to use a syslog aggregation tier and then use the Universal Forwarder on top of your syslog server(s). This gives you the most reliability, auto-load balances the data if you have a distributed setup and will not cause data loss if you need to re-start your Splunk infrastructure. I highly recommend you go this route.

If you don't have syslog servers then you can syslog directly to Splunk.

http://docs.splunk.com/Documentation/Splunk/6.4.1/Data/Monitornetworkports
http://docs.splunk.com/Documentation/Splunk/6.4.1/Data/HowSplunkEnterprisehandlessyslogdata

0 Karma
Get Updates on the Splunk Community!

Part 2: A Guide to Maximizing Splunk IT Service Intelligence

Welcome to the second segment of our guide. In Part 1, we covered the essentials of getting started with ITSI ...

Part 1: A Guide to Maximizing Splunk IT Service Intelligence

As modern IT environments continue to grow in complexity and speed, the ability to efficiently manage and ...

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...