Getting Data In

How should i write the report for Cisco device change?

thiru179
New Member

we migrated from netiq to Splunk recently, we wanted to have a same report here also such as Cisco, juniper device change.
so do i need to create any lookup or data model ?
is there any query already written for this, please help me to write the query do suggest best way to do this.

we haven't started to ingest logs of Cisco into Splunk.
do we have to have any preconfigured sourectype or splunk automatically takes the sourcetype.

0 Karma

mikaelbje
Motivator

Cisco Networks App and Cisco Networks add-on on apps.splunk.com

Read the documentation and you should be OK. Make sure you set the sourcetype as cisco:ios

Mikael

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...