Only Splunk is not enough, Apps make them More Amazing

  1. Installing Windows Server like 2012r2
  2. Configure it to connect VMWARE Bridge Network
  3. Assign proper IP address to be connected from external
  4. Turn Windows Firewall Off and Configure properly security devices to receive logs(UDP:514)
  5. Installing “Cisco Networks App for Splunk Enterprise” & “Cisco Networks Add-on for Splunk Enterprise” with help page in app

That’s all. Now you can see the result.