Getting Data In

How to set up and add CISCO L3 switches to Splunk ?

grandeurxg
New Member

Hi,

I'm very new to Splunk. My manager gave me a task how to add CISCO L3 switches to Splunk.
My manager said the switches are able to send logs to the syslog, but the syslog server does not save the logs.

Could somebody give me instructions to add CISCO L3 switches to the Splunk ?

Thank you for reading and please help.

0 Karma

dcharboneau_spl
Splunk Employee
Splunk Employee

Docs Here.
http://docs.splunk.com/Documentation/Splunk/6.3.0/Data/SyslogTCP

Splunk Addon for Cisco IOS based devices:
https://splunkbase.splunk.com/app/1467/#/documentation

Considerations:
1. Best practice to send syslog to a centralized syslog server. Install a universal forwarder on the syslog server and tail syslog log files.
2. Create an Index to store the data and set Access Control / Retention
3. Any TA's or Splunk Apps you can use? https://splunkbase.com search for cisco.

Hope this helps.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...