icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Cisco Catalyst Add-on for Splunk
SHA256 checksum (cisco-catalyst-add-on-for-splunk_200.tgz) 23e6ca22acb5a99ab0f299fc262031e114dcaabd4ecb362352ce3cbd2954846a SHA256 checksum (cisco-catalyst-add-on-for-splunk_112.tgz) aefbca58fc0449322bdb0a7b596a44ac28d55be1ceafc1b86b81d8597de4a4fd SHA256 checksum (cisco-catalyst-add-on-for-splunk_111.tgz) c03a5d50b4cbc43e60be9b2755281d92776bb684b093a8790ed1eab9f748e3a8 SHA256 checksum (cisco-catalyst-add-on-for-splunk_110.tgz) 1779b160026f52211e9524d561b189a5e59908564b16ada56c3815b238da9ee5 SHA256 checksum (cisco-catalyst-add-on-for-splunk_100.tgz) 1bb16a2d73253b354f8743b7ad403e00c27169cb8a3e5b300f68a07e2408ee26
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Cisco Catalyst Add-on for Splunk

Splunk Cloud
Overview
Details
Cisco Catalyst Add-on for Splunk collects data for different Cisco Products - **Cisco Identity Services Engine**, **Cisco Catalyst SD-WAN**, **Cisco Catalyst Center**, and **Cisco CyberVision**. The add-on parses the data from these sources and stores them into the Splunk indexes.

* Author - Cisco Systems
* Version - 1.1.1
* Build - 1
* Prerequisites - This application is dependent on **Splunk Add-on for Stream Forwarders**, **Splunk App for Stream** and **Cisco Catalyst Enhanced Netflow Add-on for Splunk** to collect Netflow Data.

Cisco Catalyst Add-on for Splunk

OVERVIEW

Cisco Catalyst Add-on for Splunk collects data for different Cisco Products - Cisco Identity Services Engine, Cisco SD-WAN, Cisco DNA Center, and Cisco Cyber Vision. The add-on parses the data from these sources and stores them into the Splunk indexes.

  • Author - Cisco Systems
  • Version - 2.0.0
  • Build - 1
  • Prerequisites - This application is dependent on Splunk Add-on for Stream Forwarders, Splunk App for Stream and Cisco Catalyst Enhanced Netflow Add-on for Splunk to collect Netflow Data.

COMPATIBILITY MATRIX

  • Browser: Google Chrome, Mozilla Firefox & Safari
  • OS: Linux, macOS, Windows
  • Splunk Enterprise Version: Splunk 9.1.x, Splunk 9.2.x, Splunk 9.3.x, Splunk 9.4.x
  • Supported Splunk Deployment: Standalone, Distributed & Cluster
  • Splunk Add-on for Stream Forwarders (Third Party Dependency): 8.1.0 & 8.0.2
  • Splunk App for Stream (Third Party Dependency): 8.1.0 & 8.0.2
  • Cisco Catalyst Enhanced Netflow Add-on for Splunk (Third Party Dependency): 1.0.0

RECOMMENDED SYSTEM CONFIGURATION

TOPOLOGY AND SETTING UP SPLUNK ENVIRONMENT

  • This app has been distributed in two parts.

    1. Cisco Catalyst Add-on for Splunk, which parses collected Syslog, Modular Input and NetFlow data.
    2. Cisco Enterprise Networking for Splunk Platform, which adds dashboards to visualize Syslog, Modular Input and NetFlow data.
  • This app can be set up in two ways:

1) Standalone Mode

  • Install the "Cisco Enterprise Networking for Splunk Platform" and "Cisco Catalyst Add-on for Splunk" on a single machine. This single machine would serve as a Search Head + Indexer + Heavy Forwarder for this setup.
  • The "Cisco Enterprise Networking for Splunk Platform" uses the data parsed by the "Cisco Catalyst Add-on for Splunk" and builds dashboards on it.

2) Distributed Environment

  • Install the "Cisco Enterprise Networking for Splunk Platform" and "Cisco Catalyst Add-on for Splunk" on the search head.
  • Install only "Cisco Catalyst Add-on for Splunk" on the heavy forwarder.
  • User needs to manually create an index on the Indexer (No need to install "Cisco Enterprise Networking for Splunk Platform" on Indexer).
  • Note: Installation of "Cisco Catalyst Add-on for Splunk" on Indexer is required in case of universal forwarder.

RELEASE NOTES

Version 2.0.0

  • Introduced a new, user-friendly custom interface for the Application Setup of the Add-On.
  • Added Client and Audit Logs inputs for DNA Center.
  • Added support for configuring Syslog inputs directly from the Add-on UI.
  • Added support for data collection for the following Cisco SD-WAN types:
    • Unified Threat Defence/Link Details
      • Unified Threat Defense Health
      • Link Health
    • Site/Tunnel Health
      • Site Health
      • Tunnel Health
      • SSE Tunnels
  • Added support for data collection for the following Cisco Identity Services Engine (ISE) types:
    • Security Group Tags
    • Authz Policy Hit
    • ISE TACACS Rule Hit
    • IP-SGT Bindings

Version 1.1.2

  • Removed timestamp parameters from client-health and network-health endpoints for Cisco DNA Center.
  • Enhanced device-health endpoint to include data for the last 15 minutes for Cisco DNA Center.

Version 1.1.1

  • Fixed indextime extractions for Cisco DNA Center.

Version 1.1.0

  • Added support for the data collection of Cisco Cyber Vision.

Version 1.0.0

  • The Add-On supports the data collection for the following products:
    • Cisco Identity Services Engine
    • Cisco SD-WAN
    • Cisco DNA Center
  • Added support for the additional log sources for Cisco SD-WAN:
    • ACL
    • SGACL
    • Audit

Lookups

  • cisco_ise_message_catalog_420.csv: Maps MESSAGE_CODE to MESSAGE_CLASS, MESSAGE_TEXT
  • cisco_ise_service.csv: Maps MESSAGE_CODE to SERVICE
  • cisco_ise_change_message_code_420.csv: Maps MESSAGE_CODE to change_type, command, object, object_attrs, object_category, result
  • cisco_ise_message_catalog_2024.csv: Maps MESSAGE_CODE to MESSAGE_CLASS, MESSAGE_TEXT, dataset_name, action, type
  • cisco_cybervision_asset_site_system_mappings: Maps host with asset_system and site_id
  • cisco_cybervision_severity_lookup: Maps severity_id with severity
  • ta_cisco_catalyst_security_group_tag_mapping: Maps ise_host with ise_server, security_group_tag and security_group_name

UNINSTALL & CLEANUP STEPS

  • Remove $SPLUNK_HOME/etc/apps/TA_cisco_catalyst
  • To reflect the cleanup changes in UI, Restart the Splunk Enterprise instance

BINARY FILE DECLARATION

  • md.cpython-37m-x86_64-linux-gnu.so - This file is generated from nested lib dependency.
  • md__mypyc.cpython-37m-x86_64-linux-gnu.so - This file is generated from nested lib dependency.

SUPPORT

Copyright (c) 2025 Cisco Systems, Inc. All rights reserved.

Release Notes

Version 2.0.0
May 30, 2025

Version 2.0.0

  • Introduced a new, user-friendly custom interface for the Application Setup of the Add-On.
  • Added Client and Audit Logs inputs for DNA Center.
  • Added support for configuring Syslog inputs directly from the Add-on UI.
  • Added support for data collection for the following Cisco SD-WAN types:
    • Unified Threat Defence/Link Details
      • Unified Threat Defense Health
      • Link Health
    • Site/Tunnel Health
      • Site Health
      • Tunnel Health
      • SSE Tunnels
  • Added support for data collection for the following Cisco Identity Services Engine (ISE) types:
    • Security Group Tags
    • Authz Policy Hit
    • ISE TACACS Rule Hit
    • IP-SGT Bindings

Version 1.1.2

  • Removed timestamp parameters from client-health and network-health endpoints for Cisco DNA Center.
  • Enhanced device-health endpoint to include data for the last 15 minutes for Cisco DNA Center.

Version 1.1.1

  • Fixed indextime extractions for Cisco DNA Center.

Version 1.1.0

  • Added suppor
Version 1.1.2
March 27, 2025

Version 1.1.2

  • Removed timestamp parameters from client-health and network-health endpoints for DNA Center.
  • Updated device-health endpoint for DNA Center to collect the data for last 15 minutes.

Version 1.1.1

  • Fixed indextime extractions for Cisco DNA Center.

Version 1.1.0

  • Added support for the data collection of Cisco Cyber Vision.

Version 1.0.0

  • The Add-On supports the data collection for the following products:
    • Cisco Identity Services Engine
    • Cisco SD-WAN
    • Cisco DNA Center
  • Added support for the additional log sources for Cisco SD-WAN:
    • ACL
    • SGACL
Version 1.1.1
Jan. 8, 2025

RELEASE NOTES

Version 1.1.2

  • Removed timestamp parameters from client-health and network-health endpoints for DNA Center.
  • Updated device-health endpoint for DNA Center to collect the data for last 15 minutes.

Version 1.1.1

  • Fixed indextime extractions for Cisco DNA Center.

Version 1.1.0

  • Added support for the data collection of Cisco Cyber Vision.

Version 1.0.0

  • The Add-On supports the data collection for the following products:
    • Cisco Identity Services Engine
    • Cisco SD-WAN
    • Cisco DNA Center
  • Added support for the additional log sources for Cisco SD-WAN:
    • ACL
    • SGACL
    • Audit
Version 1.1.0
Nov. 15, 2024
  • Added support for the data collection of Cisco CyberVision.
Version 1.0.0
Sept. 10, 2024

Version 1.0.0

  • The Add-On supports the data collection for the following products:
    • Cisco Identity Services Engine
    • Cisco Catalyst SD-WAN
    • Cisco Catalyst Center
  • Added support for the additional log sources for Cisco Catalyst SD-WAN:
    • ACL
    • SGACL
    • Audit

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.