This add-on provides a modular input for Splunk, enabling the collection of various operational insights data from Cisco's Business Critical Services (BCS) API. It allows users to ingest detailed information about their Cisco assets, devices, configurations, security advisories, and more directly into Splunk for centralized monitoring, analysis, and reporting.
Before installing and configuring this add-on, ensure you meet the following requirements:
https://api-cx.cisco.com. If you use a proxy, ensure your Splunk environment is configured to use it.TA-lcs-plug-in.tgz (or similar) file from Splunkbase..tgz file.After installation, you need to configure a new data input to start collecting data.
Navigate to Data Inputs:
TA-lcs-plug-in if displayed directly) under the list of available modular inputs.Configure Input Parameters:
cisco_bcs_data_collection).604800 (for weekly collection). Be mindful of API rate limits when setting this interval.Save: Click Add to save your input configuration.
The add-on will now attempt to authenticate with the Cisco BCS API using your provided credentials and begin collecting data at the specified interval.
This add-on retrieves data from various Cisco BCS API endpoints and indexes it into Splunk with specific sourcetypes. The following data categories are collected:
cisco:bcs:asset (Assets)cisco:bcs:device (Devices)cisco:bcs:devicegroup (Device Groups)cisco:bcs:devicegroupmember (Device Group Members)cisco:bcs:contractserial (Contract Serials)cisco:bcs:collector (Collectors)cisco:bcs:configbestpracticedetail (Details)cisco:bcs:configbestpracticerule (Rules)cisco:bcs:configbestpracticerulereference (Rule References)cisco:bcs:configbestpracticesummary (Summary)cisco:bcs:fieldnotice (Field Notices)cisco:bcs:fieldnoticebulletin (Field Notice Bulletins)cisco:bcs:hardwareendoflife (Hardware End-of-Life)cisco:bcs:hardwareendoflifebulletin (Hardware End-of-Life Bulletins)cisco:bcs:securityadvisory (Security Advisories)cisco:bcs:securityadvisorybulletin (Security Advisory Bulletins)cisco:bcs:softwareadvisoryalert (Software Advisory Alerts)cisco:bcs:softwareendoflife (Software End-of-Life)cisco:bcs:softwareendoflifebulletin (Software End-of-Life Bulletins)cisco:bcs:lastresetdetails (Last Reset Details)cisco:bcs:resetcount (Reset Count)cisco:bcs:resethistory (Reset History)cisco:bcs:riskmitigationdetails (Details)cisco:bcs:riskmitigationsummary (Summary)cisco:bcs:softwaretrackmember (Members)cisco:bcs:softwaretracksoftwaremaintenanceupgradecompliance (SMU Compliance)cisco:bcs:softwaretracksoftwaremaintenanceupgraderecommendation (SMU Recommendations)cisco:bcs:softwaretracksummary (Summary)cisco:bcs:uirdetails (UIR Details)cisco:bcs:uirsummary (UIR Summary)cisco:bcs:pindetails (PIN Details)All collected data will be indexed into the default index configured for your Splunk input, or a specific index if you override it in the input configuration.
https://api-cx.cisco.com) is hardcoded within the add-on._internal index) for messages from the TA_lcs_plug_in source for any errors or warnings during data collection.Failed to obtain JSON Web Token (JWT) errors, double-check your Client ID and Client Secret for accuracy.api-cx.cisco.com. Check firewall rules, proxy settings, and DNS resolution.As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.