This repository contains the implementation guides and supporting files for Comply to Connect (C2C) reporting with Splunk, Cisco ISE, optional Cisco Catalyst Center, optional Tenable enrichment, and optional CMRS export workflows.
Use this baseline unless your program requires a different approved stack.
| Component | Recommended Release/Version |
|---|---|
| Cisco Enterprise Networking for Splunk Platform App | 3.2.10+ |
| Cisco Catalyst Add-on for Splunk (TA) | 3.2.41+ |
| CMRS reporting supplement tooling | 1.0.6 |
Primary references:
- App guide (v3.2): C2C Reporting with Splunk/C2CReportingInstallationGuide-v3.2.md
- CMRS guide: CMRS Reporting Supplement/submit2cmrsAppInstallationGuide.md
- (Optional) Tenable audit guide: Tenable C2C HW Auditing/TenableAuditFileInstallationGuide.md
For DoW documentation please reference https://patches.csd.disa.mil/Metadata.aspx?id=139944
If you have Cisco/Splunk configuration or licensing questions please reach out to the support mailer @ cisco_c2c_support@external.cisco.com
- Current (recommended): C2C Reporting with Splunk/C2CReportingInstallationGuide-v3.2.md
- Legacy reference: C2C Reporting with Splunk/C2CReportingInstallationGuide-v3.1.md
- Current guide: CMRS Reporting Supplement/submit2cmrsAppInstallationGuide.md
Migration Note (CMRS Python Workflow): Legacy standalone CMRS Python-file workflows have been migrated into the CMRS app-based implementation. Use CMRS Reporting Supplement/submit2cmrsAppInstallationGuide.md as the source of truth for setup, configuration, and operational steps. If you are upgrading from an older deployment, follow the app guide and do not re-introduce deprecated standalone Python workflow steps.
- Tenable audit file onboarding: Tenable C2C HW Auditing/TenableAuditFileInstallationGuide.md
Follow this sequence for a clean deployment.
- Open C2C Reporting with Splunk/C2CReportingInstallationGuide-v3.2.md.
- Complete prerequisites and communications planning.
- Install the app and required TA packages.
- Configure Cisco ISE syslog and analytics repositories.
- Configure Cisco Catalyst Center inputs if used.
- Confirm Splunk indexes and inputs match your design.
Quick jump links in the v3.2 guide:
- Cisco Identity Services Engine Configuration
- Cisco Catalyst Center Configuration - Optional
- Splunk Reporting Application Configuration
- Review appendix saved-search documentation in the v3.2 guide.
- Confirm staged lookup creation and KV store population using
cisco_catalyst_kv_viewsaved search or Master Endpoint Record Dashboard to confirm data collection and storage is functional. - Validate expected scheduling cadence in your Splunk environment.
Quick jump link:
- Deploy the Tenable audit files.
- Confirm Tenable fields are flowing into the staged searches and endpoint record.
Guide:
- Implement the CMRS app installation guide.
- If migrating from older deployments, treat legacy standalone CMRS Python-file steps as deprecated and use only the app workflow.
- Complete app-specific submit2cmrs steps.
- Validate export/report output.
Guides: