You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
description: Data source object for Cisco IOS system logs. Cisco IOS logs provide operational and security telemetry from Cisco network devices (IOS, IOS XE, IOS XR, NX-OS, WLC, and APs). The Cisco Networks Add-on for Splunk (TA-cisco_ios) normalizes these events by setting proper sourcetypes and extracting fields for switches, routers, controllers, and access points; deploy the TA on indexers/HFs and search heads, and the Cisco Networks (cisco_ios) App on search heads. Supported platforms include Catalyst, ASR, ISR, Nexus, CRS, and other IOS-based devices, enabling consistent investigation, alerting, and reporting in Splunk Enterprise and Splunk Cloud. This data is ingested via SYSLOG.
6
+
description: Data source object for Cisco IOS system logs. Cisco IOS logs provide
7
+
operational and security telemetry from Cisco network devices (IOS, IOS XE, IOS
8
+
XR, NX-OS, WLC, and APs). The Cisco Networks Add-on for Splunk (TA-cisco_ios) normalizes
9
+
these events by setting proper sourcetypes and extracting fields for switches, routers,
10
+
controllers, and access points; deploy the TA on indexers/HFs and search heads,
11
+
and the Cisco Networks (cisco_ios) App on search heads. Supported platforms include
12
+
Catalyst, ASR, ISR, Nexus, CRS, and other IOS-based devices, enabling consistent
13
+
investigation, alerting, and reporting in Splunk Enterprise and Splunk Cloud. This
14
+
data is ingested via SYSLOG.
7
15
source: cisco:ios
8
16
sourcetype: cisco:ios
9
17
separator: null
10
18
supported_TA:
11
19
- name: Cisco Networks Add-on
12
20
url: https://splunkbase.splunk.com/app/1467
13
-
version: 2.7.8
21
+
version: 2.7.9
14
22
fields:
15
23
- _time
16
24
- aci_message_text
@@ -81,7 +89,8 @@ fields:
81
89
output_fields:
82
90
- user
83
91
- dest
84
-
example_log: 'Aug 20 17:10:21.639: %AAA-6-USERNAME_CONFIGURATION: user with username: attacker configured
85
-
Aug 20 17:10:21.664: %AAA-6-USER_PRIVILEGE_UPDATE: username: attacker privilege updated with priv-15
0 commit comments