we migrated from netiq to Splunk recently, we wanted to have a same report here also such as Cisco, juniper device change.
so do i need to create any lookup or data model ?
is there any query already written for this, please help me to write the query do suggest best way to do this.
we haven't started to ingest logs of Cisco into Splunk.
do we have to have any preconfigured sourectype or splunk automatically takes the sourcetype.
Cisco Networks App and Cisco Networks add-on on apps.splunk.com
Read the documentation and you should be OK. Make sure you set the sourcetype as cisco:ios
Mikael