Skip to content

Splunk Cloud

Overview

Splunk Cloud is the centralized search and alerting platform for WxCDI logs, traps, events, and CDR/CMR data.

Regional Instances

Scope Instance
US and APAC cisco-webxbu-wxcdi.splunkcloud.com
EMEA cisco-webxbu-wxcdieu.splunkcloud.com

Indexes

Index Intended Data
vos_syslog CUCM, CUC, CER, IM&P, and Expressway syslog
vos_cdr CUCM CDR and CMR records
firewall_syslog ASA, FTD, Firepower, and related firewall syslog
network_syslog Router, switch, fabric, CUBE/CUSP, and related network syslog
infra_events Infrastructure events, primarily vCenter-oriented in the source documentation
network_events Network event data
snmp_traps Enriched SNMP traps
infra_syslog Infrastructure syslog; current device coverage is incomplete
unknown_syslog Syslog that could not be matched to expected inventory metadata

Events in unknown_syslog usually indicate an inventory or enrichment mismatch that should be investigated.

Data Inputs

syslog-ng and the trap receiver write enriched data for a Splunk Universal Forwarder path. CUCM CDR/CMR uses generated SFTP tenant metadata. Expressway collectd uses its configured pushed-telemetry ingress path.

Access

For access instructions, see Operations - Splunk Access.

Administration

Index creation, retention, role mappings, parsing, capacity, and app/add-on administration are owned by the Splunk platform. Retention values were not verified in the reviewed repositories; confirm them before making data-availability commitments.