Welcome to the new Splunkbase! To return to the old Splunkbase, click here.

COLLECTION

Getting Started with Cisco Apps

See the power of Cisco + Splunk with these improved apps for Security and Observability

Security

Accelerate comprehensive visibility with best-in-class integrations

Cisco Secure Firewall App for Splunk app icon
Cisco Secure Firewall App for Splunk
By Cisco Security
****Updates July 15th, 2024*** The current Cisco Secure Firewall app is EOL, and has been replaced by the Cisco Security Cloud -- https://splunkbase.splunk.com/app/7404 The Cisco Security Cloud -- https://splunkbase.splunk.com/app/7404 -- provides eStreamer SDK integration which will provide fully qualified event support for IDS, Malware, Connection and IDS Packet. The app is a hybrid TA/App combination that will enable support for connection and management to API and Host endpoints while also provided rich analytics to compliment SOC and monitoring use cases. ************************************ Cisco Secure Firewall App for Splunk presents critical security information from Threat Defense Manager (f.k.a. Firepower Management Center (FMC)) helping analysts focus on high priority security events. The app provides a number of dashboards and tables geared towards making Firepower event analysis productive in the familiar Spunk environment. It is an alternative user interface for some, and a complementary interface for others. Cisco is committed to continuously improving this app based on your direct feedback. Major Features Include - Threat Summary Dashboard - Advanced Impact Event analysis with directionality - Network Event data dashboard with IoCs and Firewall Rule usage (Allow/Block) - Context Explorer with Geo-location Map - Link back from Malware hash to FMC for File Trajectory - Link Back to FMC for Host Profile - Filters for CIDR Blocks and Allow/Block Rule actions TELL US WHAT WILL MAKE THIS APP BETTER FOR YOU! We want your feedback and any feature requests. Please email fp-4-splunk@cisco.com with any requests.
platform
Not Available
rating
(2)
Cisco Secure Firewall App for Splunk support icon
developer supported app
Cisco Meraki Add-on for Splunk app icon
Cisco Meraki Add-on for Splunk
By Cisco Systems, Inc.
The Splunk Add-on for Cisco Meraki provides comprehensive network observability and security monitoring across your Meraki organizations. This add-on collects rich data via Cisco Meraki REST APIs and webhooks to deliver insights into network performance, security, and device health. Sample visualizations are also provided to help explore the data and create custom dashboards. The add-on provides Common Information Model (CIM) compatible knowledge to integrate with other Splunk solutions, including Splunk Enterprise Security and Splunk App for PCI Compliance. Data collection can be customized through scheduled API polling and real-time webhooks to match your monitoring requirements. Security & Event Monitoring: • Organization-wide security event tracking • Air Marshal wireless threat detection • Network device logging and audit trails • Rapid network alerts via webhooks Infrastructure & Performance Insights: • Device availability and uptime monitoring • Wireless and switching performance metrics • Ethernet status and packet loss analytics • Environmental sensor data tracking • Top device rankings by usage and utilization • Energy consumption monitoring for switches Network Operations: • Configuration change tracking • SD-WAN and VPN performance monitoring • Cellular gateway uplink status • API usage analytics and optimization • License and firmware auditing Supported Cisco Meraki Devices: • Access Points • Security Appliances • Switches • Cameras • Environmental Sensors • Cellular Gateways
platform
Not Available
rating
(2)
Cisco Meraki Add-on for Splunk support icon
cisco supported addon
Observability

Unlock more insights across any environment and any stack

Cisco Meraki Add-on for Splunk app icon
Cisco Meraki Add-on for Splunk
By Cisco Systems, Inc.
The Splunk Add-on for Cisco Meraki provides comprehensive network observability and security monitoring across your Meraki organizations. This add-on collects rich data via Cisco Meraki REST APIs and webhooks to deliver insights into network performance, security, and device health. Sample visualizations are also provided to help explore the data and create custom dashboards. The add-on provides Common Information Model (CIM) compatible knowledge to integrate with other Splunk solutions, including Splunk Enterprise Security and Splunk App for PCI Compliance. Data collection can be customized through scheduled API polling and real-time webhooks to match your monitoring requirements. Security & Event Monitoring: • Organization-wide security event tracking • Air Marshal wireless threat detection • Network device logging and audit trails • Rapid network alerts via webhooks Infrastructure & Performance Insights: • Device availability and uptime monitoring • Wireless and switching performance metrics • Ethernet status and packet loss analytics • Environmental sensor data tracking • Top device rankings by usage and utilization • Energy consumption monitoring for switches Network Operations: • Configuration change tracking • SD-WAN and VPN performance monitoring • Cellular gateway uplink status • API usage analytics and optimization • License and firmware auditing Supported Cisco Meraki Devices: • Access Points • Security Appliances • Switches • Cameras • Environmental Sensors • Cellular Gateways
platform
Not Available
rating
(2)
Cisco Meraki Add-on for Splunk support icon
cisco supported addon