All Apps and Add-ons

How to add the data of switches and routers into the Cisco Networks App for Splunk Enterprise?

splunkfly
New Member

How to configure adding the data of switches and routers into the Cisco Networks App for Splunk Enterprise?

0 Karma

gmerhej_splunk
Splunk Employee
Splunk Employee

Along with the App, you'll need to install the "Cisco Networks Add-on" and to use the sourcetype cisco:ios for the Syslog data sent from the switches and routers.

0 Karma

splunkfly
New Member

I have logs data stored on Syslog-ng ---->universal forwarder----> splunk Server
I couldn't find the feature sourcetype cisco:ios for the Syslog data sent from the switches and routers.
The Networks App looks great but I Need input the data from syslog server to splunk app, that's the challenging. If you can be help me with bit more information would helps me a lot.

0 Karma

gmerhej_splunk
Splunk Employee
Splunk Employee

You will need to manually define the sourcetype in the inputs.conf under the monitor stanza:

http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/Bypassautomaticsourcetypeassignment

0 Karma

splunkfly
New Member

is this path is correct where inputs.conf file located ?? (Splunk_Home/etc/system/local/inputs.conf)

0 Karma

gmerhej_splunk
Splunk Employee
Splunk Employee

There are many inputs.conf. However, it's better to do the configuration in Splunk_Home/etc/apps/search/local/inputs.conf

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...