All Apps and Add-ons

Cisco Networks App for Splunk Enterprise: Why does the configuration audit show "Archiving not enabled on this device"

spattenqt
Explorer

Everything in the Cisco Networks App for Splunk Enterprise is working great, except the configuration audit. It shows ARCHIVING IS NOT ENABLED ON THIS DEVICE in the cmd field, however, logging is enabled, and if I click on the "error", I can actually see the raw data in the search. Is anybody else having this problem or familiar with the solution?

0 Karma

mikaelbje
Motivator

Paste sample logs as seen in Splunk, please. Otherwise I have to speculate what your issue might be.

0 Karma

Moorrees
New Member

It seems i have the same issue.
2 switches, i think the config is the same, but i see the message " ARCHIVING NOT ENABLED ON THIS DEVICE"

0 Karma

mikaelbje
Motivator

Ok, thanks for confirming. Let's verify a few things:

  1. Do you see the facility, mnemonic, user and command fields extracted when you run your manual search? What about the event_id field?
  2. Are you running version 2.2.1 (or the newly released 2.3.0) of both Cisco Networks app for Splunk Enterprise AND Cisco Networks add-on for Splunk Enterprise?
  3. Have you made any local changes in any of the apps/add-ons? I'm asking because a refinement was done not too long ago to support config change management even when the event_id fiels is missing by resorting to using the event's _time field instead.
  4. Try version 2.3.0 of both apps to see if that helps 🙂

Mikael

0 Karma

mikaelbje
Motivator

Oh, I missed something. It looks like you are getting your syslog through TCP which is not fully supported at this time. Could you check if UDP works better?

0 Karma

spattenqt
Explorer

Entry in the app:

2015-09-09 09:48:08     1.1.1.1     console     username    vty0    1.1.1.1         ARCHIVING NOT ENABLED ON THIS DEVICE 

Actual log entries.

Sep 9 09:48:08 1.1.1.1 <189>213: Sep 9 08:53:07 CDT: %PARSER-5-CFGLOG_LOGGEDCMD: User:username logged command:interface GigabitEthernet2/0/9

Sep 9 09:48:08 1.1.1.1 <189>214: Sep 9 08:53:07 CDT: %PARSER-5-CFGLOG_LOGGEDCMD: User:username logged command:shutdown 

Sep 9 09:48:08 1.1.1.1 <189>215: Sep 9 08:53:07 CDT: %PARSER-5-CFGLOG_LOGGEDCMD: User:username logged command:no shutdown 

Sep 9 09:48:08 1.1.1.1 <189>216: Sep 9 08:53:07 CDT: %SYS-5-CONFIG_I: Configured from console by username on vty0 (125.108.185.249)
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...