We have new Cisco UCS kit and would like to process its syslogs in Splunk. Has anyone already established a set of field extractions or dashboards that they would like to share? Are there any plans for Splunk to provide any within the product? I think this is likely to be a hardware options that will grow significantly in popularity over time.
Example (scrubbed) logs:
Oct 26 16:33:02 pgce0-su-0j-b.tia.sn.local : 1001 Oct 26 16:33:02 LON: %OTIS-6-EVENT: [G2140204][054002][transition][internal][] [REX:STAGE:STALE-SUCCESS]: MARY profile configuration on peer fabric(REX-STAGE:rea:bev:OrrgYfpxhgnFowZerley:Peer)
Oct 26 16:32:52 pgce0-su-1w-a.tia.sn.local : 1001 Oct 26 15:32:52 VAN: %OTIS-3-PORT_FAILED: [D0047][cleared][port-failed][sys/switch-B/slot-1/switch-ether/port-3] ether port 3 on fabric interconnect B gwyn state: link-up, reason: Link failure or not-connected
Oct 26 16:32:52 pgce0-su-1w-a.tia.sn.local : 1001 Oct 26 15:32:52 VAN: %OTIS-3-PORT_FAILED: [D0047][cleared][port-failed][sys/switch-B/slot-1/switch-ether/port-1] ether port 1 on fabric interconnect B gwyn state: link-up, reason: Link failure or not-connected
Oct 26 16:32:51 tpr0-su-0j-b.tia.sn.local : 1001 Oct 26 16:32:51 LON: %USER-6-SYSTEM_EVE: checking user:svc_rhonda,!!!!!!!!!!!,03030.000000,01263.000000 - jefferson
Oct 26 16:32:51 tpr0-su-0j-b.tia.sn.local : 1001 Oct 26 16:32:51 LON: %USER-6-SYSTEM_EVE: checking user:max-dorinda,$1$K1jNUXPu$1bpsCt0/xDbsWSwrfHXi//,-1.000000,01263.000000 - jefferson
Oct 26 16:32:51 tpr0-su-0j-b.tia.sn.local : 1001 Oct 26 16:32:51 LON: %USER-6-SYSTEM_EVE: checking user:admin,$1$lnRiXnQe$VQ0qXvmM0CfaJBU36ZLMk/,-1.000000,01263.000000 - jefferson
Oct 26 16:32:51 tpr0-su-0j-b.tia.sn.local : 1001 Oct 26 16:32:51 LON: %USER-6-SYSTEM_EVE: checking user:ronnie,!,-1.000000,01263.000000 - jefferson
Oct 26 16:32:51 pgce0-su-0j-b.tia.sn.local : 1001 Oct 26 16:32:51 LON: %OTIS-3-OPERATIONAL_STATE_DOWN: [Y0231][major][operational-state-down][fabric/hal/A/tp-100] hal port-channel 100 on fabric interconnect A gwyn state: failed, reason: No operational members
Oct 26 16:32:46 pgce0-su-1w-a.tia.sn.local : 1001 Oct 26 15:32:46 VAN: %OTIS-3-MEMBERSHIP_DOWN: [T0025][cleared][membership-down][fabric/hal/A/tp-101/ai-slot-1-port-3] hal Member 1/3 of Port-Channel 101 on fabric interconnect A is down, membership: down
Oct 26 16:32:46 pgce0-su-1w-a.tia.sn.local : 1001 Oct 26 15:32:46 VAN: %OTIS-3-MEMBERSHIP_DOWN: [T0025][cleared][membership-down][fabric/hal/A/tp-101/ai-slot-1-port-1] hal Member 1/1 of Port-Channel 101 on fabric interconnect A is down, membership: down
Oct 26 16:32:30 pgce0-su-1w-a.tia.sn.local : 1001 Oct 26 15:32:30 VAN: %OTIS-3-LINK_DOWN: [Y0035][major][link-down][sys/switch-B/slot-1/switch-ether/port-3] ether port 3 on fabric interconnect B gwyn state: link-down, reason: Link failure or not-connected
Oct 26 16:32:30 pgce0-su-1w-a.tia.sn.local : 1001 Oct 26 15:32:30 VAN: %OTIS-3-PORT_FAILED: [D0047][major][port-failed][sys/switch-B/slot-1/switch-ether/port-3] ether port 3 on fabric interconnect B gwyn state: link-up, reason: Link failure or not-connected
... View more