Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Cisco Networks App for Splunk Enterprise
MD5 checksum (cisco-networks-app-for-splunk-enterprise_232.tgz) 4732e1e3c7667f631d09ba4467dbb227 MD5 checksum (cisco-networks-app-for-splunk-enterprise_230.tgz) f9d7d20aae6f7fd6dbbe7dcfbaa30007 MD5 checksum (cisco-networks-app-for-splunk-enterprise_221.zip) af067f1becb112bad90a6533970e55ff MD5 checksum (cisco-networks-app-for-splunk-enterprise_220.zip) f6d4a51d78ae251a1924a83972988c9f MD5 checksum (cisco-networks-app-for-splunk-enterprise_211.tgz) 41d4defd62f7baae6b12444e32213ce5 MD5 checksum (cisco-networks-app-for-splunk-enterprise_210.tgz) a34d267eff3aa180a5f82206f5a9ef58 MD5 checksum (cisco-networks-app-for-splunk-enterprise_200.tgz) 931b4afbd8467c8f1aa759cb9fad6c8c MD5 checksum (cisco-networks-app-for-splunk-enterprise_160.tgz) 43dd674ff8e947eee0c5ab38ce3f9dd9 MD5 checksum (cisco-networks-app-for-splunk-enterprise_150.tgz) ff19bb577af634675ec6f8c167830139 MD5 checksum (cisco-networks-app-for-splunk-enterprise_132.tgz) b709ea6c27d9f7221c3904a69ccc213f MD5 checksum (cisco-networks-app-for-splunk-enterprise_131.tgz) 38c56ca838efa48d42b50d32889ab350 MD5 checksum (cisco-networks-app-for-splunk-enterprise_130.tgz) 8f4745e6a20345b0745b5d14446cb76f MD5 checksum (cisco-networks-app-for-splunk-enterprise_121.tgz) 423f048f04dbb436cd8b212ad588aea8 MD5 checksum (cisco-networks-app-for-splunk-enterprise_115.tgz) 7525181e1a829c5c83969c2bb353003f MD5 checksum (cisco-networks-app-for-splunk-enterprise_113.tgz) c62de70384fa351cfd74602b4eaeaed1 MD5 checksum (cisco-networks-app-for-splunk-enterprise_111.tgz) fe51a5c4b359a22ff67fb3411ddf03ee MD5 checksum (cisco-networks-app-for-splunk-enterprise_108.tgz) ceb756d47af47aaca87dca60fb5f197e MD5 checksum (cisco-networks-app-for-splunk-enterprise_105.tgz) 2b7a6b8938b1623df5883dae236871fc MD5 checksum (cisco-networks-app-for-splunk-enterprise_100.tgz) c0125803a8256ce87a0aa98bc9d4eace MD5 checksum (cisco-networks-app-for-splunk-enterprise_012.tgz) 38392e28f18c17e3adec2db9194e45c9
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Description required

Cisco Networks App for Splunk Enterprise

Overview
Details
The Cisco Networks App for Splunk Enterprise includes dashboards, data models and logic for analyzing data from Cisco IOS, IOS XE, IOS XR and NX-OS devices using Splunk® Enterprise.

Install this App on your search head. Install the Cisco Networks Add-on (TA-cisco_ios) on your search head AND indexers/heavy forwarders.

Supported Cisco Devices:
* Cisco Catalyst series switches (2960, 3650, 3750, 4500, 6500, 6800, 7600 etc.)
* Cisco ASR - Aggregation Services Routers (900, 1000, 5000, 9000 etc.)
* Cisco ISR - Integrated Services Routers (800, 1900, 2900, 3900, 4451 etc.)
* Cisco Nexus Data Center switches (1000V, 2000, 3000, 4000, 5000, 6000, 7000, 9000 etc.)
* Cisco Carrier Routing System
* Other Cisco IOS based devices (Metro Ethernet, Industrial Ethernet, Blade Switches, Connected Grid etc.)
* Cisco WLC - WLAN Controller

107060

The Cisco Networks App includes dashboards, data models and logic for analyzing data from Cisco IOS, IOS XE, IOS XR and NX-OS devices using Splunk® Enterprise.

Please post a question on Splunk Answers and tag it with "Cisco Networks" if there is anything you would like to see in this app.

Application Details

Sourcetype(s): cisco:ios
Supported Technologies: Cisco IOS, IOS-XE, NX-OS, IOS XR devices, WLC
Supported Splunk versions: 6.1+

Installation Instructions

The Cisco Networks app can be downloaded, installed, and configured to receive Cisco IOS and WLC data by either using the Splunk app setup screen or by manually installing and configuring the app.
This app reads from the sourcetype cisco:ios defined in TA-cisco_ios

Setup and configuration

1. Install in $SPLUNK_HOME/etc/apps/cisco_ios

2. Restart Splunk

3. See the Help page in the app

Getting Help

Release Notes

Version: 2.3.2

##### New features Cisco Networks includes the following new features: - Added some more panels to the Security -> ACL dashboard ##### Fixed issues Version 2.3.2 of the Cicso Networks app fixes the following issues: - Documentation for certification ##### Known issues Version 2.3.2 of the Cisco Networks app has the following known issues: - Unable to return raw events in Splunk Enterprise 6.3.0 using searches such as sourcetype=cisco:ios unless in Fast Mode. This is due to a bug in Splunk Enterprise 6.3.0 and the Vendor Message Lookup CSV file. Workarounds (choose one): - Upgrade your servers to Splunk Enterprise 6.3.1 or higher - Rename TA-cisco_ios/default/limits.conf.example as TA-cisco_ios/default/limits.conf your Search Head and Indexers

Feb. 23, 2016, 8:57 a.m.

Platform Independent

6.5, 6.4, 6.3, 6.2

Version: 2.3.0

##### New features Cisco Networks includes the following new features: - Route flapping table added to the Routing Dashboard - AP logging now supported - Security ACL now does a sum of packets instead of counting rows ##### Fixed issues Version 2.3.0 of the Cicso Networks app fixes the following issues: - Change management transactions now resorts to using _time if event_id is missing. - Changed result field for authentication events to vendor_action for CIM compliance. Also changed in the TA - All searches now use eventtypes instead of sourcetype=cisco:ios ##### Known issues Version 2.3.0 of the Cisco Networks app has the following known issues: - Unable to return raw events in Splunk Enterprise 6.3 using searches such as sourcetype=cisco:ios unless in Fast Mode. This is due to a bug in Splunk Enterprise 6.3 and the Vendor Message Lookup CSV file. Workaround: Rename TA-cisco_ios/default/limits.conf.spec as TA-cisco_ios/default/limits.conf your Search Head and Indexers

Sept. 11, 2015, 6:43 a.m.

Platform Independent

6.3, 6.2

Version: 2.2.1

##### New features Cisco Networks includes the following new features: - Added WLC/IOS toggle to the overview page. UPDATE YOUR Cisco Networks Add-on too!

April 7, 2015, 12:03 p.m.

Platform Independent

6.2

Version: 2.2.0

##### New features Cisco Networks includes the following new features: - Added facility category lookup file based on http://www.cisco.com/c/en/us/td/docs/ios/15_0sy/system/messages/15sysmg/sm15syovr.html - Added variable name lookup file (not in use yet) - Better documentation ##### Fixed issues Version 2.2.0 of the Cicso Networks app fixes the following issues: - Fixed static search on one single device for Smart Call Home events in the Device view - Removed unused searches - Wireless view corrected to get MAC addresses correctly output - Improvements to get the app Splunk Certified ##### Known issues Version 2.2.0 of the Cisco Networks app has the following known issues: - None known

Feb. 5, 2015, 1:26 p.m.

Platform Independent

6.2

Version: 2.1.1

+++ 2.1.1 (2014-12-05) Bug fixes: * Time picker for Auditing Time Drift + CDP neigbors fixed (it was explicit)

Dec. 5, 2014, 9:38 a.m.

Platform Independent

6.2

Version: 2.1.0

++ What's New +++ 2.1.0 (2014-10-30) Features: * NAME CHANGED TO Cisco Networks. Also download the latest TA-cisco_ios! * More filters in the dashboards * DOT1X now with more graphs

Dec. 3, 2014, 10:18 a.m.

Platform Independent

6.2, 6.1

Version: 2.0.0

++ What's New +++ 2.0.0 (2014-09-19) Features: * CIM 4.0 Compliance. MANY fields have changed names. You may need to change your custom searches * Lots of new features. Dashboards have been fixed up, drilldowns enhanced, more Smart Call Home support MAKE SURE YOU REMOVE EARLIER VERSIONS OF THE CISCO IOS APP BEFORE INSTALLING THIS VERSION!

Sept. 23, 2014, 1:55 p.m.

Platform Independent

6.2, 6.1

Version: 1.6.0

++ What's New +++ 1.6.0 (2014-07-21) Features: * Device/s dashboard changed. Includes data collected with Smart Call Home. Bug fixes: * Routing dashboard no longer auto refreshes * Drilldown now works better in the Event Analysis! * CSV file moved out of the TA to the main app

July 21, 2014, 12:23 p.m.

Platform Independent

6.1

Version: 1.5.0

++ What's New +++ 1.5.0 (2014-05-08) Features: * Added more fields to the data model * Added an Event Analysis Dashboard to Auditing using the new lookups from TA-cisco_ios. * Auditing -> Best Practice Deviations has been removed * Map visualizations added to Security -> ACL

May 8, 2014, 9:40 a.m.

Platform Independent

6.1

Version: 1.3.2

++ What's New +++ 1.3.2 (2014-04-23) Added a new overview page (overview_postprocess_searches_no_pivot) as a workaround for users having problems with Data Model powered searches not displaying (Splunk defect SPL-83310) - THIS IS SLOW! Bug fixes: * Removed some unneccessary files. * Moved Performance panels into a common performance_dashboard Features: * Preliminary support for IP SLA events (Performance dashboard) * Optical transceiver attenuation monitoring (Switching -> Dashboard)

April 24, 2014, 8:19 a.m.

Platform Independent

6.1, 6.0

Version: 1.3.1

++ What's New +++ 1.3.1 (2014-04-17) Bug fixes: * 802.1x euthentications now renamed to 802.1x events, no longer a child of "User" * Various small changes

April 17, 2014, 9:37 a.m.

Platform Independent

6.0

Version: 1.3.0

+++ 1.3.0 (2014-04-04) Features: * Now relies on Splunk 6! Data models are in use Bug fixes: * Device dashboard now fixed

April 4, 2014, 8:47 a.m.

Platform Independent

6.0

Version: 1.2.1

+++ 1.2.1 (2014-02-17) Features: Started work on a new Device dashboard +++ 1.2.0 (2014-01-09) Features: * Moved props, transforms etc to the TA. YOU NOW NEED THE TA ON YOUR SEARCH HEAD ALONGSIDE THE APP! +++ 1.1.6 (2013-10-10) Features: * Started creating Data Models for Splunk 6.0 Bug fixes: * Top ACL logs now counts num_packets

Feb. 17, 2014, 11:53 a.m.

Platform Independent

6.0, 5.0

Version: 1.1.5

+++ 1.1.5 (2013-09-20) Features: * IOS XR support

Sept. 20, 2013, 11:31 a.m.

Platform Independent

6.0, 5.0, 4.3

Version: 1.1.3

+++ 1.1.3 (2013-08-12) Bug fixes: * Fixed bug that also captured events that were in the body of ACS events * Now captures events from switches with a subfacility +++ 1.1.2 (2013-07-22) Features: * Added wireless - more to come

Aug. 14, 2013, 6:40 a.m.

Platform Independent

5.0, 4.3

Version: 1.1.1

+++ 1.1.1 (2013-05-27) Features: * Add a reliable_time=true/false based on presence of *: * More CIM compliance * Fixed ACL logging for log-input +++ 1.1.0 (2013-05-16) Features: * Smart Install view added to Auditing * Added FHRP to Switching (no extractions yet) +++ 1.0.9 (2013-04-26) Features: * Moved a few things around * Etherchannel added to performance

June 21, 2013, 12:25 p.m.

Platform Independent

5.0, 4.3, 4.2

Version: 1.0.8

+++ 1.0.8 (2013-04-23) Features: * Added Switching nav * Added Security nav * Added extractions for DOT1X - this will be getting transaction tracking soon Bug fixes: * Fixed general extraction to handle integers in facility and mnmenonic +++ 1.0.7 (2013-04-17) Features: * Regex support for WLC * Added stack manager +++ 1.0.6 (2013-04-12) Features: * Now extracts login successes and failures

April 25, 2013, 12:28 a.m.

Platform Independent

5.0, 4.3, 4.2

Version: 1.0.5

+++ 1.0.5 (2013-04-05) Features: * Added device restart/boot table to Auditing dashboard. Thanks jaoui +++ 1.0.4 (2013-04-04) Bug fixes: * Fixed subfacility extraction +++ 1.0.3 (2013-03-28) Bug fixes: * Minor under the hood improvements +++ 1.0.2 (2013-03-26) Features: * More extractions added, not yet in any views Bug fixes: * device_time extraction has been re-worked a bit to avoid pulling in the wrong values +++ 1.0.1 (2013-03-25) Bug fixes: * Better time matching in place for the time drift view. Now matches numerous formats and is fast, but shows all results

April 5, 2013, 8:34 a.m.

Platform Independent

5.0, 4.3, 4.2

Version: 1.0.0

The Cisco IOS app can be downloaded, installed, and configured to receive Cisco IOS data by either using the Splunk app setup screen or by manually installing and configuring the app. This app reads from the sourcetype cisco_ios defined in TA-cisco_ios 1.0.0 (2013-03-21) Features: * The app has been split up into two parts, one App for the search head and a TA for indexers (TA-cisco_ios) * Added BGP, EIGRP and MPLS LDP extractions * Added time drift in Auditing Currently requires the device time to be in this format Mar 21 19:29:47.320 CET or Mar 21 19:29:47.320 The search is quite slow * Added tags * Added time picker for each view * Host search added for config change transactions 0.1.7 (2013-03-05) Features: * OSPF adjacency change regex added: adjchg * OSPF adjacency change panel added to Routing -> Dashboard * CDP neighbor add/remove eventtypes and extractions for Nexus switches added * CDP neighborhood panel for Nexus switches added to Datacenter -> Dashboard * Added all events to index "ios" Bug fixes: * Interface matching fixed, didn't capture multi slot/chassis interfaces * CIM compliance for src_ip, src_vlan and dest_vlan

March 25, 2013, 11:30 a.m.

Platform Independent

5.0, 4.3, 4.2

Version: 0.1.2

Feb. 3, 2013, 9:25 a.m.

Platform Independent

5.0, 4.3, 4.2

1,430
Installs
22,801
Downloads
Share Subscribe LOGIN TO DOWNLOAD
Version
2.3.2
Category
IT Operations
Security, Fraud & Compliance
Product Support
Splunk Enterprise
Content Type
App
Splunk Versions
6.5
6.4
6.3
6.2
Licensing
Creative Commons CC BY-NC-SA 4.0
Platforms
Platform Independent
Built by
Mikael Bjerkeland
Contact Developer
Subscribe Share

Splunk Certified

Splunk's App Certification program uses a specific set of criteria to evaluate the level of quality, usability and security your app offers to its users. In addition, we evaluate the documentation and support you offer to your app's users.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2016 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.