I have Splunk 6.1 and a small Cisco network (10 network devices, 2 x WLC with 50 APs) and have installed both the Cisco networks Add on and Cisco Networks App; and am not quite clear if it is all working properly despite reviewing and trying to follow the App Help.
The Cisco Networks app is sparsely populated with data with > 50% unpopulated. Not sure if this is because this is only the data is available or what.
Here is a summary of the relevant splunk config shows:
- both apps installed (and reboot performed)
- Data Inputs (syslog data ) are configured as UDP Port 514 (the App instructions say choose another port but this was done previously to app install) - with sourcetype 'syslog' - no option appears for cisco:ios
- Sourcetype Cisco:SmartCallHome is set for TCP input on port 8989
- Switches have had their configurations set as shown in help (for 3750x all the commands are supported; not all features are supported for some others).
Results:
- from the base search interface, the range of fields (src_interface,mnemonic, message text....) and the sourcetype = cisco:ios suggest logs are being properly indexed with cisco relevant interpretations
- in the Cisco networks APP, most of the panels are not populated as if data is not available. No inventory info (although ATHome is believed to be configured and working), site names etc. NOt clear how these names are set.
- in The switching drop down, there is some data
- Wireless - empty panels. Not clear if every AP needs to send logging info or just WLCs (we have just configured the latter)
Questions:
a) How is the Cisco Add On - 'called up / specified' for the data inputs as above? Seems to be working; but perhaps I don't understand how the indexing rules and fields are determined as being applicable (though it seems to be working)
b) How does one debug a data input - to see what data is being received to enable troubleshooting
c) Wireless - any ideas of what makes this panel produce a useful overview?
... View more