Install the Content Pack for Cisco Enterprise Networks

High-level steps to install the Content Pack for Cisco Enterprise Networks.

Complete the following steps to install the Content Pack for Cisco Enterprise Networks.

  1. Review the deployment requirements.
  2. Ensure that you meet the prerequisites.
  3. Install the content pack.

Prerequisites

Prerequisites for installing the Content Pack for Cisco Enterprise Networks.

You must meet the following prerequisites to install the Content Pack for Cisco Enterprise Networks. For version requirements, see the previous section.
PrerequisiteDescriptionInstructions
1. Back up your environment.Create a full backup of your IT Service Intelligence (ITSI) environment in case you need to uninstall the content pack later.Create a full backup of ITSI.
2. Install the Splunk App for Content Packs.The content pack requires the Splunk App for Content Packs.Install the Splunk App for Content Packs.
3. Install the Cisco Catalyst Add-On for Splunk.The content pack requires data collected from the Cisco Catalyst Add-On for Splunk.See the Details tab of the Splunkbase listing.
4. Configure the required data inputs in the Cisco Catalyst Add-on for Splunk.The content pack requires the following data inputs to be configured in the Cisco Catalyst Add-on for Splunk:
  • Device Health

  • Issue

  • Security Advisory

  • Site Topology

To configure the data inputs:
  1. From the Splunk Enterprise main menu, select Apps, then Cisco Catalyst Add-on for Splunk.

  2. In the Catalyst Center tile, select Configure Application.

  3. Use the Inputs tab to configure the data inputs.

For optimal monitoring, set the collection interval for your data inputs to the minimum interval required by the Cisco Catalyst Center.

5. Install the Cisco Meraki Add-on for Splunk.The content pack requires data collected from the Cisco Meraki Add-on for Splunk.See Installation in the Cisco Meraki documentation.
6. Configure the required data inputs in the Cisco Meraki Add-on for Splunk.

The content pack requires the following data inputs to be configured in the Cisco Meraki Add-on for Splunk:

  • Organizations

  • Organizations Networks

  • Assurance Alerts

  • Wireless Packet Loss by Device

  • Device Availabilities Change History

See Configure Inputs in the Cisco Meraki documentation.

For optimal monitoring, change the collection interval for your data inputs to the following intervals:

  • Organizations: 3,600 seconds

  • Organizations Networks: 3,600 seconds

  • Wireless Packet Loss by Device: 600 seconds

  • Device Availabilities Change History: 900 seconds

  • Assurance Alerts: 600 seconds

Install the content pack

Steps to install the Content Pack for Cisco Enterprise Networks.

Complete the following steps to install the Content Pack for Cisco Enterprise Networks.
  1. From the ITSI main menu, select Configuration, then Data Integrations.
  2. Select the Content library tab.
  3. Under Splunk Supported Content Packs, select Cisco Enterprise Networks.
  4. Follow the on-screen instructions to install the content pack.
    Note: Saved searches are disabled by default in the installation flow, but certain saved searches must be enabled to monitor Cisco Enterprise Network entities. To selectively enable these searches, see Enable Cisco Catalyst Center and Cisco Meraki entity discovery searches.