Cisco CDR Reporting and Analytics




Experts and Splunk P.S. Instructions

Some folks really *are* too cool for school.

If you already pretty much know what you are doing in Splunk, maybe all you need is a checklist to follow.

If you are going to follow this, follow it to the end.  If you got halfway through and decided “Meh, I’ll just wing it from here”, I will be able to tell because your installation will not work properly, and I will not be happy.


  • Splunk is running and you have admin access to it.  Or you can open cloud tickets for the environment.
  • There is an SFTP server somewhere,
    • which you can log in to (or can get access to)
    • with an SFTP account you can use to receive the CDR data from CUCM
    • and which has a Splunk forwarder on it configured to send to your indexing tier.  (We strongly suggest UF, but HF will work if it’s already installed)
  • You can make Billing Server configuration changes to CUCM, or know someone who can.

Checklist for installation – on prem

Checklist for installation – cloud

Checklist for installation – Autobahn

Next Steps

After set up, the app should start working pretty much immediately (obviously it’s slightly dependent on call volume, but it only takes one completed call to make Browse Calls show … one completed call.)

Check out the following couple of simple set up steps that can really make it more useful too –

  • Sites – maps network locations (via IP addresses in CIDR notation) into “places”.
  • Groups – maps numbers to names, groups and subgroups.

I hope this helps.



If you have any comments at all about the documentation, please send it in to