If you have the TA installed as well as the App all you need to do is make sure your inputs logs to sourcetype syslog.. You should also make sure your Splunk user has access to the "ios" index and searches it by default.
My suggestion would be to read the parts regarding sources, sourcetypes and indexes in the Splunk documentation. The app will work out of the box as soon as you have the basics sorted out. Good luck!
Also... Inputs??? I thought the Switch is already sending the Syslog to Splunk Server??? Do I still need an Input??
I have more problems with these App's for Splunk.... I thought the App should take care of the Splunk user access to the "ios" index..??? I don't even know where to change that... Thanks...
As the TA is still pending approval from Splunk you cannot download it from Splunkbase just yet, but in the meantime you can get it from github. Check http://github.com/inspired
The Cisco 6504 Switch is configured for Syslog to goto the Splunk Server... But the Cisco App still don't show any Info??? I see info from a search on Splunk from the Switch, but nothing from the App.... Don't see any other configuration to do on the App??