Skip to content

automine/TA-cisco_acs

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

8 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Technology Add-on for Cisco ACS

Description

This app provides CIM compliant field extractions, eventtypes and tags for Cisco ACS events. This does not include any dashboards or views.

Index-time operations

This app contains index-time operations for timestamping, linebreaking and host rewriting. These are, however, commented out, and should be reviewed prior to use.

Sourcetypes

This TA expects a sourcetype of cisco:acs.

Installation

This TA can be installed by untarring to the $SPLUNK_HOME/etc/apps directory, uploading via the web interface or by using Deployment Server.

Product versions

This TA was created and tested with the following versions of Cisco ACS:

  • Versions 5.x
  • Versions 4.x

History

1.2

Initial release

1.3

Made changes to event types (thanks to Vlad from Splunk!)

1.5

Changes to field aliases for changes in fieldalias behavior in Splunk 7.2 (thanks to danverandy)

1.5.2

Added extractions for Port and Device_Port

About

This app provides CIM field extractions, eventtypes and tags for Cisco ACS events.

Resources

Stars

Watchers

Forks

Packages

 
 
 

Contributors