This app implements various field extraction configuration and Sideview conventions so as to allow syslog-formatted Expressway CDR data to be not only searched in Splunk effectively, but also to be pulled into Sideview's commercial "Cisco CDR Reporting and Analytics" solution on Splunk and investigated and analyzed there.
NOTE that this Supporting App is designed to be always deployed with Sideview's "Supporting Add-on for Expressway CDR" ALSO deployed on the Indexing tier. That "Add-on" component contains crucial index-time configuration to index the CDR into Splunk correctly, and that index-time configuration is NOT duplicated in this app here. Therefore if you intend to set up a standalone deployment you will need both the TA and the SA.
These two apps are furthermore designed to work with Sideview's commercial "Cisco CDR Reporting and Analytics" app. When all three components are present and deployed to the right tiers, users can navigate, troubleshoot and build ad-hoc charts and reports around the Expressway data, within the the Cisco CDR app's complex user interfaces.
Categories
Investigative, IT Operations
Created By
Sideview, LLC - Partner, an official Splunk Partner
Resources
Log in to report this app listing