Cisco CDR Reporting & Analytics | Installation Notes
If you have Splunk admins, make friends with them if you haven’t already. Regardless these steps should only take a couple of minutes.
If you or your Splunk admins have a preferred way of creating indexes, just follow those steps. If not and you only have a standalone Splunk instance, follow the instructions below.
Note (1): If Browse More Apps does not work, for instance, because you are on an air-gapped network or if Splunkbase integration is disabled. That’s fine. Just go to the Splunkbase page for Canary and download it as a a .tgz file, then do the same for Cisco CDR Reporting and Analytics. Assuming your account is a Splunk admin, you can install them by going to the Manage Apps page and clicking Install App From File.
Note (2): If instead of Install it says View on Splunkbase, this means your Splunk user account does not have the ability to install new apps. Engage the help of your local Splunk admin team.
Note (3): If you’re using Splunk Cloud and it says you cannot install our apps, contact us, because it means.… something is wrong. Our apps are approved for Splunk Cloud, so we will investigate and reach out to the Cloud folks and get you going.
If you used a custom index name earlier (instead of “cisco_cdr”), you’ll need to go to Splunk’s Settings menu > Advanced Search > Search macros. Find the macro named “custom_index” and edit it to reflect your index name.
For users who will need and expect full use of the app’s features and who will need to run the apps’s more sophisticated reports, it is best to give their accounts the “power” user role. In terms of capabilities and quotas, at least for the senior users on the team, their user accounts should have at least a 500MB dispatch directory size, allow at least 5 concurrent searches, and have the schedule_search capability. These three requirements can then be achieved simply by granting these users the “power” role.
We also recommend that at least one user on the team be able to do “Schedule PDF Delivery” in the Splunk SimpleXML, and this requires the “list_settings” capability in addition to “schedule_search”.
You should now have both the Canary and Cisco CDR Reporting and Analytics apps installed. Don’t worry that the Cisco CDR landing page complains that you have no data yet, the next step is to enable the data collection system.