<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Cisco Security Suite in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61605#M2049</link>
    <description>&lt;P&gt;Splunk 4.1.7 build 95063. &lt;BR /&gt;
Security Suite:&lt;/P&gt;

&lt;P&gt;build = 96705&lt;/P&gt;

&lt;P&gt;I downloaded Splunk last week.  I bet I need to be using 4.2. I'm not sure why I have 4.1!&lt;/P&gt;</description>
    <pubDate>Thu, 17 Mar 2011 21:34:42 GMT</pubDate>
    <dc:creator>jgauthier</dc:creator>
    <dc:date>2011-03-17T21:34:42Z</dc:date>
    <item>
      <title>Splunk Cisco Security Suite</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61602#M2046</link>
      <description>&lt;P&gt;I noticed that Splunk for Cisco Security Suite is available and replaced the previous named product.&lt;/P&gt;

&lt;P&gt;I removed the old product my apps, installed this one and restarted Splunk.&lt;/P&gt;

&lt;P&gt;When I went to use the App, Splunk indicated the app was not set up.
So, I went to the set up page, I see there is nothing to do, so I click "Save".&lt;/P&gt;

&lt;P&gt;Then this error is presented:&lt;/P&gt;

&lt;P&gt;"Your entry was not saved. The following error was reported: undefined."&lt;/P&gt;

&lt;P&gt;Thanks for any help!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2011 07:39:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61602#M2046</guid>
      <dc:creator>jgauthier</dc:creator>
      <dc:date>2011-03-17T07:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cisco Security Suite</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61603#M2047</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;There should be a hyperlink on Setup page that will take you to version 1.0.0 of Cisco Security Suite (http://splunkbase.splunk.com/apps/All/4.x/Suite/app:Cisco+Security+Suite)&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;The error that you see should be benign.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;What version of Splunk are you on?&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;-Dmitrii&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2011 08:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61603#M2047</guid>
      <dc:creator>dmitrii4splunk</dc:creator>
      <dc:date>2011-03-17T08:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cisco Security Suite</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61604#M2048</link>
      <description>&lt;P&gt;What version of Splunk are you using (e.g. 4.2 build 96430)?&lt;/P&gt;

&lt;P&gt;Also, could you provide the build number of the Cisco Security Suite app? You can find the build number in the file at &lt;STRONG&gt;etc/apps/Splunk_CiscoSecuriySuite/default/app.conf&lt;/STRONG&gt; under the install stanza:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[install]
state = enabled
is_configured = false
build = 96430
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 17 Mar 2011 08:17:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61604#M2048</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2011-03-17T08:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cisco Security Suite</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61605#M2049</link>
      <description>&lt;P&gt;Splunk 4.1.7 build 95063. &lt;BR /&gt;
Security Suite:&lt;/P&gt;

&lt;P&gt;build = 96705&lt;/P&gt;

&lt;P&gt;I downloaded Splunk last week.  I bet I need to be using 4.2. I'm not sure why I have 4.1!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2011 21:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61605#M2049</guid>
      <dc:creator>jgauthier</dc:creator>
      <dc:date>2011-03-17T21:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cisco Security Suite</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61606#M2050</link>
      <description>&lt;P&gt;Do have any of the other Cisco apps or the MaxMind app installed?&lt;/P&gt;

&lt;P&gt;I just tried the same version of the Cisco Security Suite on 4.1.7 with no apps installed and it worked fine for me. I'm wondering if some app or combination of apps triggers the problem.&lt;/P&gt;

&lt;P&gt;Like dmitri4splunk said, that error is benign. Nevertheless, it would be nice if we could get that fixed.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2011 10:24:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61606#M2050</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2011-03-18T10:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cisco Security Suite</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61607#M2051</link>
      <description>&lt;P&gt;I upgraded to splunk 4.2 build 96430.   The only other apps I have installed are Splunk for Nagios, the Cisco for Firewalls (for the extraction bits), and the splunk license usage.&lt;/P&gt;

&lt;P&gt;I did verify the error appears with this build, too.&lt;BR /&gt;
Understanding that its benign, how do I use the app?  Everytime I go to the app, it tells me it needs to be configured.   So, I try to save, and an endless circle ensues!&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2011 19:46:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61607#M2051</guid>
      <dc:creator>jgauthier</dc:creator>
      <dc:date>2011-03-18T19:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cisco Security Suite</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61608#M2052</link>
      <description>&lt;P&gt;You can bypass the setup screen by setting is_configured to true in app.conf. To do so, open &lt;STRONG&gt;etc/apps/Splunk_CiscoSecuriySuite/local/app.conf&lt;/STRONG&gt; (or create it if it does not exist) and enter the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[install]
is_configured = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You may need to restart Splunk after editing the config file. Splunk won't force you to view the setup screen once it recognizes the app is considered configured.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2011 22:54:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61608#M2052</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2011-03-18T22:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cisco Security Suite</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61609#M2053</link>
      <description>&lt;P&gt;Could you be so kind to let me know what platform (Linuz, Mac, etc.) you are on? I want to replicate the issue so that I can fix it and am wondering if this retains to a particular platform.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2011 22:55:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61609#M2053</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2011-03-18T22:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cisco Security Suite</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61610#M2054</link>
      <description>&lt;P&gt;Absolutely.  This is a windows 2008 R2 x64 server.&lt;BR /&gt;
I am willing to work with you to identify/resolve if needed. I am pretty flexible.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2011 23:41:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61610#M2054</guid>
      <dc:creator>jgauthier</dc:creator>
      <dc:date>2011-03-18T23:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cisco Security Suite</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61611#M2055</link>
      <description>&lt;P&gt;I encounter a similar problem. I followed instruction on 'Setup screen example using a custom endpoint', and get the same error message when I save configuration changes on Web UI.&lt;/P&gt;

&lt;P&gt;Content of my restmap.conf,&lt;/P&gt;

&lt;P&gt;[admin:myendpoint]
match=/appset
members=appsettings
[admin_external:appsettings]
handlertype = python
handlerfile = App_python_handler.py
handleractions = list, edit&lt;/P&gt;

&lt;P&gt;Content of my App_python_handler.py,&lt;/P&gt;

&lt;P&gt;import splunk.admin as admin
import splunk.entity as en
class ConfigApp(admin.MConfigHandler):
  def setup(self):
    if self.requestedAction == admin.ACTION_EDIT:
      for arg in ['field_1', 'field_2_boolean', 'field_3']:
        self.supportedArgs.addOptArg(arg)
  def handleList(self, confInfo):
    confDict = self.readConf("appsettings")
    if None != confDict:
      for stanza, settings in confDict.items():
        for key, val in settings.items():
          if key in ['field_2_boolean']:
            if int(val) == 1:
              val = '0'
            else:
              val = '1'
          if key in ['field_1'] and val in [None, '']:
            val = ''
          confInfo[stanza].append(key, val)
  def handleEdit(self, confInfo):
    name = self.callerArgs.id
    args = self.callerArgs
    if int(self.callerArgs.data['field_3'][0]) &amp;lt; 60:
      self.callerArgs.data['field_3'][0] = '60'
    if int(self.callerArgs.data['field_2_boolean'][0]) == 1:
      self.callerArgs.data['field_2_boolean'][0] = '0'
    else:
      self.callerArgs.data['field_2_boolean'][0] = '1'
    if self.callerArgs.data['field_1'][0] in [None, '']:
      self.callerArgs.data['field_1'][0] = ''&lt;BR /&gt;
    self.writeConf('appsettings', 'setupentity', self.callerArgs.data)
admin.init(ConfigApp, admin.CONTEXT_NONE)&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2011 18:08:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cisco-Security-Suite/m-p/61611#M2055</guid>
      <dc:creator>lhy719</dc:creator>
      <dc:date>2011-04-12T18:08:14Z</dc:date>
    </item>
  </channel>
</rss>

