Getting Data In

Which addon to install to onboard Cisco Catalyst 8500-12x router logs into Splunk ?

dm1
Contributor

I need to onboard Cisco Catalyst 8500 router logs into Splunk. When I was looking for addons, I found the below addons that seem relevant 

  1. Cisco Catalyst Add-on for Splunk - This is preferred as its Cisco built and supported.
    https://splunkbase.splunk.com/app/7538
  2. Then there is this addon Add-on for Cisco Network Data - https://splunkbase.splunk.com/app/1467, but it is unsupported.

The instructions in the Cisco built addon are not very clear on how to onboard the router logs. 

Can someone please help?

Tags (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dm1 ,

until today, I always used the second one in many hundreds of project without any issue.

the fact that it isn't unsupported it's a new for me, but probably it was an oversight of mine.

The first one is Cisco supported so you could use it.

About instuctions for ingestion, I'm not a network specialist, but Catalysts, as other network appliances, should send their logs by syslog, so you can directly receive syslogs using Splunk, in an Heavy Forwarder, or (better),creating an rsyslog input that writes syslogs in a file that it is read by Splunk.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...