This Supporting Add-on defines index-time settings to ingest syslog-formatted CDR records from Cisco Expressway into Splunk. It is to be deployed on your Splunk Indexers (or if you are using a Heavy Forwarder and forwarding cooked data to your indexes, installed on that HF).
It is most effective when also deployed with two other apps on the Splunk Search Head(s) or Search Head Cluster:
a) Sideview's Supporting App for Cisco Expressway, and
b) Sideview's commercial "Cisco CDR Reporting and Analytics" app.
With these pieces in place the Sideview apps on the search head implement a general purpose investigation and reporting solution for this data.
NOTE: There are also some references in the app's config to other sourcetypes cisco_expressway_cdr_csv and/or cisco_expressway_cdr_json. These are still under development.
Categories
Investigative, IT Operations
Created By
Sideview, LLC - Partner, an official Splunk Partner
Resources
Log in to report this app listing