All Apps and Add-ons

Cisco IOS App - Multiple Instances on same Splunk Server

glaffoonPU
New Member

Currently runnin the IOS app and have our switches/routers and WLCs working correctly. However, the data from the WLCs is causing the dashboard to lose its effectiveness with routers/switches due to the chatty behavior of the WLCs. We were wanting to know if there was a way to install a second instance of the IOS app on the same splunk server and have one look at an index just for the WLCs and the other look at an index for the Routers/switches.

Any thoughts?

0 Karma

mikaelbje
Motivator

I'd just like to let you know that version 2.2.1 of the Cisco Networks App for Splunk Enterprise used in combination with Cisco Networks Add-on for Splunk Enterprise will now give you a toggle in the overview page to select between IOS or WLC events 🙂 Try it out!

rsennett_splunk
Splunk Employee
Splunk Employee

That's the answer, then. 🙂 I did not know this! Upvoted.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma

mikaelbje
Motivator

Thanks rsennett for your suggested solution. It's definitely the quick way to go and will give value through learning.

I've heard this once or twice before and I see this in a lot of customer installs, so I will consider adding a toggle in the overview page to include/exclude WLC events. To do this I need to be able to identify the WLC, something we don't do currently as the IOS and WLC log format is quite identical. One possibility would be an EVAL to change the product field to WLC if the two fields filename and filename_line are present. I will look into this shortly 🙂

Regards,
Mikael, author of the Networks app

0 Karma

glaffoonPU
New Member

Thanks for you information. What you have said makes sense. I will proceed in that direction.

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Excellent. If you would like to earn yourself some Answers Karma points... come back here when you've solved your problem... add the solution as an answer (so others can benefit from your success) and accept your own answer. 🙂

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Something to consider... While your proposal suggests that you are quite new to Splunk, the IOS app is very clearly written, in a quite uncomplicated way. A very good way to advance your Splunk skills would be to take a look at what's driving the dashboard in question. (you haven't mentioned which one). Click on Edit>Edit Panels. Take a look at the search or pivot for the panels where you would like to see the WLC separated out... if it is a search, run the search by itself in the search view... if it is a pivot, run it in pivot. Take a look at the fields available to you, and consider what might identify one type of event as opposed to another. Once you identify that, you could, just filter the unwanted data out of the search. The simple, yet inefficient way would be to add NOT "whatever" to the left of the first pipe. If the data can be identified by the presence of a particular field you could more efficiently exclude it or include the ones you want deliberately by naming the field. Perhaps clone the dashboard first, and mess with a copy to get it the way you want it...

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

If you installed a second copy of the app (which would take a bit of fakery) you would still have to edit it to a point that, forgive me... sounds like it might be beyond your current Splunk Skillset. (and I think it only uses one sourcetype and doesn't refer to index at all... ) Makes more sense to edit the existing panels.

Even without really being familiar with the data, if you lay out some specifics here "which panel, and give a sample event" you'll get tons of help as to how to filter things the way you would like it.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...