Hi @inessa40408 , I cannot help you in Cisco network devices configuration, but in Spunk, you can use Cisco network Add-On ( https://splunkbase.splunk.com/app/1467 ) to correctly parse the logs. u...
See more...
Hi @inessa40408 , I cannot help you in Cisco network devices configuration, but in Spunk, you can use Cisco network Add-On ( https://splunkbase.splunk.com/app/1467 ) to correctly parse the logs. usually these logs are ingested configuring the Cisco network devices to send their logs to a Splunk receiver using syslog. To receive syslog, you can use Splunk network inputs ( https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Monitornetworkports ), if you have few logs, otherwise you should configure an rsyslog receiver that writes logs in files read by Splunk ( https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Data/Monitorfilesanddirectories ). For the dashboards they depend on what you need to monitor, anyway the Splunk App for Cisco Network Devices could help you: https://splunkbase.splunk.com/app/1352 Ciao. Giuseppe