All Apps and Add-ons

Some devices are not indexing, after upgrade 10.5.

jean_tomaz
Explorer

Hi. Some devices are not indexing, after upgrade 10.5.
I saw that when disable the app, my devices begin indexing.
Ex: Devices like Cisco Catalyst 6500.

Can you help-me ?

0 Karma

mikaelbje
Motivator

Hi,
Sounds like your events are indexing, but not matched correctly by the regex.
Cou*ld you please do the following:
- Identify the device that is not matched
*
- Search it using index=* host=HOSTNAME_OF_DEVICE
- Send me the raw event that was not matched so that I can investigate it further

The input you have provided me so far is not enough alone to troubleshoot your issue, so always include a sample log event.

Mikael

jean_tomaz
Explorer

Perfect. Now is running correctly!!!
Thanks! 😃

0 Karma

mikaelbje
Motivator

So change your user/role to search the ios index by default, then you won't have to specify index=ios
Please remember to vote the answer

0 Karma

jean_tomaz
Explorer

Ok,the search index=ios sourcetype=cisco:ios is running correctly. This search showed all devices events.

0 Karma

mikaelbje
Motivator

Ok, so please try the following search:

index=ios sourcetype=cisco:ios

Does that return anything?

0 Karma

jean_tomaz
Explorer

I have installed the Technology Add-on. Search using index=* host=HOSTNAME_OF_DEVICE is running correctly, after reboot my server. Using search index=ios are showed the devices. But, using search sourcetype="cisco:ios" is not running.
I have devices with sourcetype="syslog". When disable the APP Cisco IOS, my devices are showed in the search sourcetype="syslog".

0 Karma

mikaelbje
Motivator

Ok, I tested your events against the regex and they match.

Could you please provide a screenshot of the whole search window?
Did you install the Technology Add-On?
Did you make sure your user/role searches in the ios index by default?

0 Karma

jean_tomaz
Explorer

Dear, Mikael.
The raw events are below.

Apr 9 17:20:30 192.168.10.251 170: 000145: Apr 9 17:20:34.451 GMT-3: %PARSER-5-CFGLOGLOGGEDCMD: User:admin logged command:shutdown Apr 9 17:20:30 192.168.10.251 169: 000144: Apr 9 17:20:34.447 GMT-3: %PARSER-5-CFGLOGLOGGEDCMD: User:admin logged command:shutdown Apr 9 17:20:24 192.168.10.251 168: 000143: Apr 9 17:20:28.691 GMT-3: %PARSER-5-CFGLOGLOGGEDCMD: User:admin logged command:switchport mode access Apr 9 16:06:58 192.168.10.251 157: 000132: Apr 9 16:07:04.059 GMT-3: %SYS-5-CONFIG_I: Configured from console by admin on vty0 (192.168.10.111)

[]'s

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...