Splunk Cloud
Overview
Splunk Cloud is the centralized search and alerting platform for WxCDI logs, traps, events, and CDR/CMR data.
Regional Instances
| Scope | Instance |
|---|---|
| US and APAC | cisco-webxbu-wxcdi.splunkcloud.com |
| EMEA | cisco-webxbu-wxcdieu.splunkcloud.com |
Indexes
| Index | Intended Data |
|---|---|
vos_syslog |
CUCM, CUC, CER, IM&P, and Expressway syslog |
vos_cdr |
CUCM CDR and CMR records |
firewall_syslog |
ASA, FTD, Firepower, and related firewall syslog |
network_syslog |
Router, switch, fabric, CUBE/CUSP, and related network syslog |
infra_events |
Infrastructure events, primarily vCenter-oriented in the source documentation |
network_events |
Network event data |
snmp_traps |
Enriched SNMP traps |
infra_syslog |
Infrastructure syslog; current device coverage is incomplete |
unknown_syslog |
Syslog that could not be matched to expected inventory metadata |
Events in unknown_syslog usually indicate an inventory or enrichment mismatch that should be investigated.
Data Inputs
syslog-ng and the trap receiver write enriched data for a Splunk Universal Forwarder path. CUCM CDR/CMR uses generated SFTP tenant metadata. Expressway collectd uses its configured pushed-telemetry ingress path.
Access
For access instructions, see Operations - Splunk Access.
Administration
Index creation, retention, role mappings, parsing, capacity, and app/add-on administration are owned by the Splunk platform. Retention values were not verified in the reviewed repositories; confirm them before making data-availability commitments.