All Apps and Add-ons

Cisco Networks App for Splunk Enterprise: Why does the configuration audit show "Archiving not enabled on this device"

spattenqt
Explorer

Everything in the Cisco Networks App for Splunk Enterprise is working great, except the configuration audit. It shows ARCHIVING IS NOT ENABLED ON THIS DEVICE in the cmd field, however, logging is enabled, and if I click on the "error", I can actually see the raw data in the search. Is anybody else having this problem or familiar with the solution?

0 Karma

mikaelbje
Motivator

Paste sample logs as seen in Splunk, please. Otherwise I have to speculate what your issue might be.

0 Karma

Moorrees
New Member

It seems i have the same issue.
2 switches, i think the config is the same, but i see the message " ARCHIVING NOT ENABLED ON THIS DEVICE"

0 Karma

mikaelbje
Motivator

Ok, thanks for confirming. Let's verify a few things:

  1. Do you see the facility, mnemonic, user and command fields extracted when you run your manual search? What about the event_id field?
  2. Are you running version 2.2.1 (or the newly released 2.3.0) of both Cisco Networks app for Splunk Enterprise AND Cisco Networks add-on for Splunk Enterprise?
  3. Have you made any local changes in any of the apps/add-ons? I'm asking because a refinement was done not too long ago to support config change management even when the event_id fiels is missing by resorting to using the event's _time field instead.
  4. Try version 2.3.0 of both apps to see if that helps 🙂

Mikael

0 Karma

mikaelbje
Motivator

Oh, I missed something. It looks like you are getting your syslog through TCP which is not fully supported at this time. Could you check if UDP works better?

0 Karma

spattenqt
Explorer

Entry in the app:

2015-09-09 09:48:08     1.1.1.1     console     username    vty0    1.1.1.1         ARCHIVING NOT ENABLED ON THIS DEVICE 

Actual log entries.

Sep 9 09:48:08 1.1.1.1 <189>213: Sep 9 08:53:07 CDT: %PARSER-5-CFGLOG_LOGGEDCMD: User:username logged command:interface GigabitEthernet2/0/9

Sep 9 09:48:08 1.1.1.1 <189>214: Sep 9 08:53:07 CDT: %PARSER-5-CFGLOG_LOGGEDCMD: User:username logged command:shutdown 

Sep 9 09:48:08 1.1.1.1 <189>215: Sep 9 08:53:07 CDT: %PARSER-5-CFGLOG_LOGGEDCMD: User:username logged command:no shutdown 

Sep 9 09:48:08 1.1.1.1 <189>216: Sep 9 08:53:07 CDT: %SYS-5-CONFIG_I: Configured from console by username on vty0 (125.108.185.249)
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...