All Apps and Add-ons

Cisco Networks

aalaa
Path Finder

Hello ,

I installed the Cisco Network application to monitor the routing events but nothing to display in the dashboard of this application, we need to monitor all OSPF protocol events .

we activate these commands router :

router ospf 1
log-adjacency-changes detail
(config)#archive
(config-archive)#log config
(config-archive-log-cfg)#logging enable

==> is it the necessary cisco config ??

PS : Type router : Cisco CISCO3945-CHASSIS (revision 1.0) with C3900-SPE150/K9
Cisco IOS Software, C3900 Software (C3900-UNIVERSALK9-M), Version 15.1(4)M2, RELEASE SOFTWARE (fc1),

Your help is much appreciated
Thank you !

Tags (1)
0 Karma

nickhills
Ultra Champion

Can you post your logging server config - also, how are you collecting syslog? - Directly to splunk, or via a syslog server with a UF?

If my comment helps, please give it a thumbs up!
0 Karma

aalaa
Path Finder

This is the config in the router cisco :
router ospf 1
log-adjacency-changes detail
(config)#archive
(config-archive)#log config
(config-archive-log-cfg)#logging enable

I collected the log by syslog

0 Karma

nickhills
Ultra Champion

You should have a line which says something like: (config)#logging 192.168.0.30 where that IP or DNS name is the name of your syslog server.

Have you confirmed that syslog messages are actually being sent to the syslog server?

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...