Refine your search:

Thanks For Downloading!

Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows:

Windows: Decompress the downloaded file using a tool like 7-Zip and place the resulting folder into %PROGRAMFILES%\Splunk\etc\apps. Then restart Splunk using the splunk restart command or the GUI.

Unix/Linux: Decompress the downloaded file using a tool like tar -xvf and place the resulting folder into $SPLUNK_HOME/etc/apps. Then restart Splunk using the splunk restart command or the GUI.

Description

The Splunk App for Cisco UCS app is used to gather data from one or more Cisco UCS Managers. This release is a PREVIEW version, and as such, does not reflect the final product.

ABOUT THIS APP

The Splunk App for Cisco UCS app is used to gather data from one or more Cisco UCS Managers. This release is a PREVIEW version, and as such, does not reflect the final product. To be more specific:

  • The TA-CiscoUcsSyslog collector app is in a stable state. However, it will be obsoleted in a future release and replaced by streaming events using the UCS XML API.
  • The TA-CiscoUcsPs collector app is in a stable state. However, it is planned for this app to be ported from using Windows PowerShell to a cross-platform language (Python), so it will necessarily change.
  • It is expected that the field names used by the above apps (especially Splunk fields like index and eventtype, and most if not all UCS data fields) will remain the SAME in future versions of this app. thus easing upgrades.
  • The base app has two mature dashboards ("Home", and "Faults"). These will change very little in subsequent versions (subject to customer feedback). The remaining dashboards and reports are in various stages of development and will change drastically.

SCREENSHOTS

Home Dashboard

Faults Dashboard


REQUIREMENTS

The Technology Add-On "TA-CiscoUcsPs" has the following requirements:

  • Windows Server 2003 or later
  • Windows PowerShell version 2 or later
  • PowerShell execution policy must be set to RemoteSigned (or less restrictive, e.g. Unrestricted. See <http://msdn.microsoft.com/en-us/library/windows/desktop/bb648601(v=vs.85).aspx>)
  • Cisco UCS PowerTool version 0.9.8 or later (<http://developer.cisco.com/web/unifiedcomputing/pshell-download>)
  • Splunk Universal Forwarder version 4.0 or later
  • The collector system must have network access (HTTP/HTTPS) to one or more UCS Managers which are to be Splunked.
  • A read-only user ID and password for collecting data from UCS Manager

The syslog Technology Add-On "TA-CiscoUcsSyslog" has the following requirements:

  • Each UCS Manager should be configured to send syslog messages to your Splunk Indexer(s). Complete instructions can be found here: <http://www.cisco.com/en/US/products/ps10281/products_configuration_example09186a0080ae0f24.shtml>. Use the "info" level and the default facility settings.
  • Note: This requirement will change in the future. Syslog is a "legacy" means of gathering data from UCS. Future versions will instead use the XML API to stream data from UCS in a manner similar to syslog (i.e., it will be pushed), however, the data will be richer.

HOW TO INSTALL

  1. Unpack the app archive to $SPLUNK_HOME$/etc/apps on your Search Head
  2. Copy the TA-CiscoUcsSyslog folder from appserver/addons to $SPLUNK_HOME$/etc/apps on your Indexer
  3. Copy the TA-CiscoUcsPs folder from appserver/addons to $SPLUNK_HOME$/etc/apps on a Windows system (the "collector") which meets the above requirements and is running the Universal Forwarder.
    1. Copy the file ciscoucs.conf.template from TA-CiscoUcsPs/default/ to local/, and rename to "ciscoucs.conf".
    2. Read the file to understand the layout, and using the format described therein, edit the UcsmAuthRealm setting, specifying one "authority realm" (comma-separated) per each set of credentials to be supplied to your UCS Managers.
    3. For each auth realm, specify one or more servers (comma-separated), one username, and one password.
    4. Don't forget to remove or comment out any examples from the template which are not in use.
  4. Restart Splunk instances as needed.
  5. Login to Splunk web, go to the new app and inspect the home dashboard to ensure that data is being indexed.

The above tasks can (and should) be performed by using the Splunk Deployment Server or another configuration management tool.

KNOWN ISSUES

  • Home dashboard: paginator shows incorrect number of pages (related to SPL-36073, fixed in v5)
  • Several dashboards are at very early stages of development and do not reflect a final product.

Versions and Release Notes

Version 0.3 (current version - updated Jul 25, 2012)

posted 25 Jul '12, 09:15

halr9000's gravatar image

halr9000 ♦
50127
accept rate: 40%

new version 25 Jul '12, 09:15


4 Reviews:
4 reviews, 0 ratings, average 0

Has anyone got this to work. All my stuff show blank. But if i do a search for "ciscoUCS" then i get data. But none of the main fields.

comments (0)

reviewed 28 Jan, 14:28

childebrandt's gravatar image

childebrandt
111
accept rate: 0%

i wasn't able to make the app work, yet. can it even work on a linux host? Or is the powershell TA not optional?

Regards and thanks, Markus

comments (0)

reviewed 17 Jan, 05:50

mstegmueller's gravatar image

mstegmueller
1
accept rate: 0%

Has anyone had success using the Splunk UCS app with the UCS emulator? Thanks.

comments (0)

reviewed 12 Jan, 06:24

jaimeporras's gravatar image

jaimeporras
11
accept rate: 0%

Hi,

Good start on the UCS dashboard.

I got UCS data coming in on faults page, and to some extent the power, temp, and networking tabs. I am not getting any information on the home tab though. Any ideas?

Thanks, Joe

comments (1)

reviewed 29 Aug '12, 15:34

virtualpony's gravatar image

virtualpony
613
accept rate: 50%

Joe, somehow I missed this comment. We have a new version coming out very shortly which should address your issues. The PowerShell-based scripted input had a bug which did affect some installs and caused a symptom like you describe.

(29 Nov '12, 20:44) halr9000 ♦
Your review

Did you find this app useful?

Preview toggle preview

Copyright © 2005-2012 Splunk Inc. All rights reserved.