Expressway - Cisco Expressway
Overview
Cisco Expressway C/E provides remote access and traversal between external clients or Webex services and internal UC applications.
Monitoring
Method
expwy-exporter API collection plus the Expressway collectd path through expwy-prometheus.
Metrics Collected
- Expressway service and traversal-zone health
- Registrations, sessions, and certificate state
- CPU, memory, storage, and interface health
- API, collectd, and scrape freshness
Grafana Dashboards
Logging
Log Source
Expressway C/E nodes send VOS syslog and collectd telemetry; trap support must be verified against live configuration.
Splunk Index
vos_syslog for syslog. Collectd uses its configured Splunk ingestion path.
Key Log Queries
index=vos_syslog device_type="expwy" device_name="<device_name>"
Alerting
Grafana Alert Rules
| Alert Name | Severity | Description |
|---|---|---|
| Expressway service health | Varies | Traversal, resource, and API/collectd conditions. |
| Scrape down | Critical | Detects loss of Expressway collection. |
Splunk Alerts
| Alert Name | Severity | Description |
|---|---|---|
| Expressway VOS events | Varies | Traversal and platform events from vos_syslog. |
Notification Flow
Expressway → Grafana/Splunk → EMS (KeepHQ) → [notification channels]
Inventory
- Repository: VOS inventory
- Update Method: Generated from the managed VOS/Ansible inventory.
- Update Cadence: On Expressway inventory change through pull request.