All Apps and Add-ons

Cisco network app not interpret for DHCP and ARP inspection dashboards. maybe eventtype problem?

victordiaz
New Member

Hello,

I have some problems to show data in this dashboards. in the main page dashboard (event count, severity, etc)the data are ok!

When i try tho show data of DHCP, the dashboard not have any data. The search query is:
eventtype="cisco_ios-dhcp_snooping" num_packets=* | strcat dvc " " src_int dvc_src_int | timechart sum(num_packets) BY dvc_src_int

If i try this: eventtype="cisco_ios-dhcp_snooping" num_packets=*
Also i not have data.

I think that is because eventtype=cisco_ios-dhcp_snooping is not correctly configured (i Used de Add-on)

Can any help me please!!

0 Karma

mikaelbje
Motivator

Can you try the development version of the add-on at https://github.com/inspired/TA-cisco_ios ?

I looked at the code and it looks correct in the dev version

0 Karma

victordiaz
New Member

Hello,

Thanks for the reply!

I install de Add-on of App store. In the documentation of github page they say that can i downloaded the add-on :Download the Cisco Networks Add-on at https://apps.splunk.com/app/1467/.

i think thats is the same of the app store installation or your solution is tho downloaded the code in .zip of the github page and instally manually.

In mi cisco ASR i dont have the service call-homeconfigured, maybe thi is mkandatory??

Thanks you for the help.

0 Karma

mikaelbje
Motivator

Yes, download the code as zip. Do not follow the link back to Splunkbase apps. The code downloaded will come in a folder called TA-cisco_ios-master. Just rename this folder to TA-cisco_ios. Make sure you delete the old folder first.

Call home is not mandatory.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...