Getting Data In

Monitoring Cisco FlexVPN Tunnels

VegasSplunky
Loves-to-Learn

There seems to be a lot of information about other Cisco VPN technologies (ASA/Firepower/Anyconnect) but I am not finding much relating to FlexVPN (site-to-site) tunnels. Maybe I am not looking up the correct terminology. FlexVPN runs on IOS XE.

I have logging configured the same as far as using logging trap informational (default) and noticed that we seem to not be getting a lot of data relating to the specifics with the tunnels, negotiations, etc., from a raw syslog perspective.

What we would like to be able to do is monitor the tunnels so whenever a tunnel is brought up, taken down, or source (connection) IPs change. Possibly other things we haven't though of yet, hoping to encounter someone else who has used the same technologies and has something already built out.

Thank you in advance.

Labels (2)
0 Karma

VegasSplunky
Loves-to-Learn

Honestly kind of surprised here especially with the recent Cisco acquisition since this is using a Cisco technology. I feel like there would be more input on how we can do this.

0 Karma

VegasSplunky
Loves-to-Learn

No ideas?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...