I can see traffic on the firewall between the 2 hosts but nothing comes up when searching the sourcetype of cisco:ucs
@pcuenco
Can you please confirm sourcetype and index name in Configurations > Tasks??
Can you please try sourcetype=cisco:ucs:*
?
https://docs.splunk.com/Documentation/AddOns/released/CiscoUCS/Configureinputs
I manually created an index (cisco) and a sourcetype (cisco:ucs) and I get 0 events when I search that string.
Cisco UCS Task:
Polling Interval: 300
Source Type: cisco:ucs
Index: cisco