User Community Feedback

Submitted ideas will be evaluated by our product teams for upcoming releases and will be responded to so you know where things stand. For product support, please use the community forums or contact TAC.

NOTE: All Cisco employees & Channel Partners must enter Ideas through this Ideas Portal.

Address Delay in Webex logs coming into Splunk that make use of Webex API's

We recently configured and setup an integration with webex logs coming into Splunk. We can confirm those logs are now coming in, but we have noticed some unusual behavior with the various sourcetype logs associated with the webex history service, which give us the meaningful events/fields needed to build alerts and dashboards. the data coming in is 2-5 days older. The splunk input is configured to use an API call to pull data across at a maximum of every 24 hour period (most regular setting available) so would expect the data to be at least a day old at the maximum.We use the Splunk plugin which make API calls to retrieve the data from webex and send to Splunk.Plugin provides options to retrieve data for active scheduled sessions or historical meetings.

We checked classical reports in webex admin portals and found they shows the most recent data. can we make use of are preliminary history APIs that classic reports using to get the most recent data.Plugin information can be found at


https://github.com/splunk/ta-cisco-webex-meetings-add-on-for-splunk/blob/master/README.md


  • Guest
  • Oct 12 2021