Getting Data In

How should i write the report for Cisco device change?

thiru179
New Member

we migrated from netiq to Splunk recently, we wanted to have a same report here also such as Cisco, juniper device change.
so do i need to create any lookup or data model ?
is there any query already written for this, please help me to write the query do suggest best way to do this.

we haven't started to ingest logs of Cisco into Splunk.
do we have to have any preconfigured sourectype or splunk automatically takes the sourcetype.

0 Karma

mikaelbje
Motivator

Cisco Networks App and Cisco Networks add-on on apps.splunk.com

Read the documentation and you should be OK. Make sure you set the sourcetype as cisco:ios

Mikael

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...