Cisco CDR Reporting & Analytics | Docs

Expressway CDR

Cisco Expressway generates its own CDR, it has some very interesting metadata about your Expressway calls, and long story short it’s possible to ingest these records into Splunk. 

First of all, please reach out to us to say hello (info@​sideviewapps.​com) , and please do send over any and all details around what visibility and insight(s) your team is hoping to get out of your Expressway CDR. This is very much an area of active development for us so if we need to, we’ll be able to make changes very quickly. 

First it’s worth checking the Expressway box(es) to see if CDRs are already configured. Someone may have already set things up to send them out via syslog (and if so you should learn that now. Then go find them and bring them a nice present). 

  1. Go to Maintenance > Logging
  2. In the Logging Options section, if the Call Detail Records field is set to Off then CDR’s are not being generated.

Or, the other two values it might be set to, represent your options for generating them: 

  1. Services and Logging in this configuration the CDRs are stored locally for 7 days and then deleted. The records are accessible from the local Event Log, and are also sent as INFO messages via syslog, if you are sending syslog out externally.
  2. Service Only in this configuration the CDR’s are only stored locally for 7 days and then deleted. The records are not accessible through the web user interface and can only be read via the Expressway REST API

Getting the Sideview Apps

  1. First, our TA goes on your Indexer tier. It’s full name is Supporting Add-on for Expressway” and you can download it from splunkbase here.
  2. Next there is a separate SA app that goes on your Search Head tier. It’s the Supporting App for Expressway” and here is its separate listing on Splunkbase.
     

You’ll find more detail in the README for both apps and pay special attention if for some reason you’re using a Heavy Forwarder. 

As with our other Supporting Apps”, it augments the main Cisco CDR Reporting and Analytics” app. When installed alongside the main app, and after you have the Expressway data flowing in and enabled in Admin > enable/​disable data types”, you can click around in the app UI to investigate and generate charts and dashboards on your expressway traffic, in the same way that you do for your CallManager CDR and CUBE CDR.

To give you an example though, here is a screenshot showing an intraday calling pattern for a filtered search result of about 700 expressway calls.

Related

Installation Notes

Have your cake and eat it too!  Trust Webex with your calls, but pull all the metadata into Sideview's app in Splunk, for ad-hoc investigation, charting and flexible dashboards.