<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235538#M26512</link>
    <description>&lt;P&gt;I forgot to add, that I have a distributed setup with a search head and an indexer.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Mar 2016 21:41:26 GMT</pubDate>
    <dc:creator>molinarf</dc:creator>
    <dc:date>2016-03-07T21:41:26Z</dc:date>
    <item>
      <title>Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235535#M26509</link>
      <description>&lt;P&gt;I recently migrated my Splunk from Windows 2012 to Linux (CentOS). I am currently running Splunk Enterprise 6.3.2. I added the Splunk add on for Cisco IPS ver. 2.1.5 and had to manually configure the inputs.conf file just to get Splunk to do a successful connection to the IPS. Now that the SDEE subscription is valid, I get this error:&lt;/P&gt;

&lt;P&gt;ERROR - Connecting to sensor - X.X.X.2: Traceback (most recent call last): File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/get_ips_feed.py", line 99, in run sdee.open() File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 187, in open self._request(params) File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 163, in _request data = urllib2.urlopen(req) File "/opt/splunk/lib/python2.7/urllib2.py", line 154, in urlopen return opener.open(url, data, timeout) File "/opt/splunk/lib/python2.7/urllib2.py", line 431, in open response = self._open(req, data) File "/opt/splunk/lib/python2.7/urllib2.py", line 449, in _open '_open', req) File "/opt/splunk/lib/python2.7/urllib2.py", line 409, in _call_chain result = func(*args) File "/opt/splunk/lib/python2.7/urllib2.py", line 1240, in https_open context=self._context) File "/opt/splunk/lib/python2.7/urllib2.py", line 1197, in do_open raise URLError(err) URLError: &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:59:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235535#M26509</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2020-09-29T08:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235536#M26510</link>
      <description>&lt;P&gt;This looks similar to a bug (ADDON-6014) that was encountered after upgrade to Splunk 6.3 (the root cause was a newer version of Python in Splunk 6.3 which contained changes to the urllib2 library that TA uses). &lt;/P&gt;

&lt;P&gt;That was resolved in Cisco IPS version 2.1.5 -- which you mention you have in your original question. &lt;/P&gt;

&lt;P&gt;My initial hypothesis would be that the IPS query code was not updated appropriately. Was the IPS TA installed from scratch or upgraded from a previous version? Either should be fine but I'm trying to learn more about the environment to determine what could be causing this. Do you have a support case open? In this specific case, it may be easier to help by reviewing a diag. &lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 21:29:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235536#M26510</guid>
      <dc:creator>bwooden</dc:creator>
      <dc:date>2016-03-07T21:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235537#M26511</link>
      <description>&lt;P&gt;The IPS TA was installed from scratch on this newly built server. I opened a support case as well, #&lt;BR /&gt;&lt;BR /&gt;
000328995 .&lt;BR /&gt;
I have also been looking at the pySDEE.py file in /opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee and noticed that the file references TLSv1_1 rather than SSLv3 and I don't know if that is an issue. I made a change to the file to use the SSLv3 and if that doesn't clear up the problem, I will change it back.&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:59:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235537#M26511</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2020-09-29T08:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235538#M26512</link>
      <description>&lt;P&gt;I forgot to add, that I have a distributed setup with a search head and an indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 21:41:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235538#M26512</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2016-03-07T21:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235539#M26513</link>
      <description>&lt;P&gt;Are your using Splunk 6.4 ? &lt;/P&gt;

&lt;P&gt;If so the new python 2.7.11 libs seem to bork out the Base64 password conversion section of pySDEE.py located in:&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee&lt;/P&gt;

&lt;P&gt;So... here is what I did do change it: &lt;/P&gt;

&lt;P&gt;Replace 164 of the file with the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;req.add_header('Authorization', "BASIC %s" % (self._b64pass.replace('\n', '')))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Worked like a charm &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;- INFO - Attempting to connect to sensor: ips-2
Wed Apr 27 09:35:57 2016 - INFO - Successfully connected to: -ips-2
Wed Apr 27 09:35:57 2016 - INFO - Checking for existing SubscriptionID on host: ips-1
Wed Apr 27 09:35:57 2016 - INFO - No existing SubscriptionID for host: -ips-1
Wed Apr 27 09:35:57 2016 - INFO - Attempting to connect to sensor: -ips-1
Wed Apr 27 09:35:57 2016 - INFO - Successfully connected to: -ips-1
Wed Apr 27 09:35:59 2016 - INFO - Successfully connected to: ips-1
Wed Apr 27 09:35:59 2016 - INFO - host="candeal-ips-1" SessionID="48436f106cdef9a21176c4151b7bfacd" SubscriptionID="sub-3-5bae0fff"
Wed Apr 27 09:35:59 2016 - INFO - Successfully connected to: - INFO - Attempting to connect to sensor: candeal-ips-2
Wed Apr 27 09:35:57 2016 - INFO - Successfully connected to: candeal-ips-2
Wed Apr 27 09:35:57 2016 - INFO - Checking for existing SubscriptionID on host: candeal-ips-1
Wed Apr 27 09:35:57 2016 - INFO - No existing SubscriptionID for host: candeal-ips-1
Wed Apr 27 09:35:57 2016 - INFO - Attempting to connect to sensor: candeal-ips-1
Wed Apr 27 09:35:57 2016 - INFO - Successfully connected to: candeal-ips-1
Wed Apr 27 09:35:59 2016 - INFO - Successfully connected to: candeal-ips-1
Wed Apr 27 09:35:59 2016 - INFO - host="candeal-ips-1" SessionID="48436f106cdef9a21176c4151b7bfacd" SubscriptionID="sub-3-5bae0fff"
Wed Apr 27 09:35:59 2016 - INFO - Successfully connected to: ips-2
Wed Apr 27 09:35:59 2016 - INFO - host="candeal-ips-2" SessionID="92422ed39a6138baab166b468b6d532c" SubscriptionID="sub-3-848eb720"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Let me know how you make out .&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:33:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235539#M26513</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2020-09-29T09:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235540#M26514</link>
      <description>&lt;P&gt;Oh ya and either try connecting with TLSv1_1 or TLSv1 first . &lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 16:00:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235540#M26514</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2016-04-27T16:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235541#M26515</link>
      <description>&lt;P&gt;Hi, could you please clarify this change:&lt;/P&gt;

&lt;P&gt;Replace 164 of the file with the following :&lt;BR /&gt;
req.add_header('Authorization', "BASIC %s" % (self._b64pass.replace('\n', '')))&lt;/P&gt;

&lt;P&gt;This means that the original line:&lt;BR /&gt;
req.add_header('Authorization', "BASIC %s" % (self._b64pass))&lt;/P&gt;

&lt;P&gt;Will be replaced with:&lt;BR /&gt;
req.add_header('Authorization', "BASIC %s" % (self._b64pass.replace('\n', '')))&lt;/P&gt;

&lt;P&gt;??&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:51:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235541#M26515</guid>
      <dc:creator>tequilalinux</dc:creator>
      <dc:date>2020-09-29T09:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235542#M26516</link>
      <description>&lt;P&gt;Yes your assumption is correct -this should fix the issue when running 6.4&lt;/P&gt;

&lt;P&gt;Let me know how you make out .&lt;/P&gt;

&lt;P&gt;Kristofer &lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2016 10:49:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235542#M26516</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2016-06-04T10:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235543#M26517</link>
      <description>&lt;P&gt;Hi Kristofer, &lt;/P&gt;

&lt;P&gt;I still have this issue and no data coming from CISCO IPS&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Sat Jun  4 11:57:09 2016 - ERROR - Connecting to sensor - X.X.X.X: Traceback (most recent call last):   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/get_ips_feed.py", line 99, in run     sdee.open()   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 187, in open     self._request(params)   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 163, in _request     data = urllib2.urlopen(req)   File "/opt/splunk/lib/python2.7/urllib2.py", line 154, in urlopen     return opener.open(url, data, timeout)   File "/opt/splunk/lib/python2.7/urllib2.py", line 437, in open     response = meth(req, response)   File "/opt/splunk/lib/python2.7/urllib2.py", line 550, in http_response     'http', request, response, code, msg, hdrs)   File "/opt/splunk/lib/python2.7/urllib2.py", line 475, in error     return self._call_chain(*args)   File "/opt/splunk/lib/python2.7/urllib2.py", line 409, in _call_chain     result = func(*args)   File "/opt/splunk/lib/python2.7/urllib2.py", line 558, in http_error_default     raise HTTPError(req.get_full_url(), code, msg, hdrs, fp) HTTPError: HTTP Error 401: Unauthorized 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 04 Jun 2016 17:09:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235543#M26517</guid>
      <dc:creator>tequilalinux</dc:creator>
      <dc:date>2016-06-04T17:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235544#M26518</link>
      <description>&lt;P&gt;You have an email address ? I will just email you the .py file ... &lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2016 18:08:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235544#M26518</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2016-06-04T18:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235545#M26519</link>
      <description>&lt;P&gt;Create a throw away gmail account and I will send the .py to you . Replace the one you have . &lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2016 18:09:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235545#M26519</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2016-06-04T18:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235546#M26520</link>
      <description>&lt;P&gt;Remember you need to restart Splunk after every change to a .py file - did you restart ?&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2016 18:11:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235546#M26520</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2016-06-04T18:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235547#M26521</link>
      <description>&lt;P&gt;Got it, &lt;A href="mailto:tequilalinux@gmail.com"&gt;tequilalinux@gmail.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2016 18:11:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235547#M26521</guid>
      <dc:creator>tequilalinux</dc:creator>
      <dc:date>2016-06-04T18:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235548#M26522</link>
      <description>&lt;P&gt;Just sent ... &lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2016 18:20:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235548#M26522</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2016-06-04T18:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235549#M26523</link>
      <description>&lt;P&gt;Thanks klaxdal, I replaced the file and now I get this error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Sat Jun  4 13:27:37 2016 - ERROR - Connecting to sensor - X.X.X.X : Traceback (most recent call last):   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/get_ips_feed.py", line 99, in run     sdee.open()   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 188, in open     self._request(params)   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 164, in _request     data = urllib2.urlopen(req)   File "/opt/splunk/lib/python2.7/urllib2.py", line 154, in urlopen     return opener.open(url, data, timeout)   File "/opt/splunk/lib/python2.7/urllib2.py", line 431, in open     response = self._open(req, data)   File "/opt/splunk/lib/python2.7/urllib2.py", line 449, in _open     '_open', req)   File "/opt/splunk/lib/python2.7/urllib2.py", line 409, in _call_chain     result = func(*args)   File "/opt/splunk/lib/python2.7/urllib2.py", line 1240, in https_open     context=self._context)   File "/opt/splunk/lib/python2.7/urllib2.py", line 1197, in do_open     raise URLError(err) URLError:  

Sat Jun  4 13:27:34 2016 - INFO - Successfully connected to: X.X.X.X

Sat Jun  4 13:27:34 2016 - INFO - Attempting to connect to sensor: X.X.X.X
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 04 Jun 2016 18:30:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235549#M26523</guid>
      <dc:creator>tequilalinux</dc:creator>
      <dc:date>2016-06-04T18:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235550#M26524</link>
      <description>&lt;P&gt;Yes, I restarted splunk after .py change and this is what I get&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Sat Jun  4 14:48:03 2016 - ERROR - Connecting to sensor - X.X.X.X: Traceback (most recent call last):   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/get_ips_feed.py", line 99, in run     sdee.open()   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 188, in open     self._request(params)   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 164, in _request     data = urllib2.urlopen(req)   File "/opt/splunk/lib/python2.7/urllib2.py", line 154, in urlopen     return opener.open(url, data, timeout)   File "/opt/splunk/lib/python2.7/urllib2.py", line 431, in open     response = self._open(req, data)   File "/opt/splunk/lib/python2.7/urllib2.py", line 449, in _open     '_open', req)   File "/opt/splunk/lib/python2.7/urllib2.py", line 409, in _call_chain     result = func(*args)   File "/opt/splunk/lib/python2.7/urllib2.py", line 1240, in https_open     context=self._context)   File "/opt/splunk/lib/python2.7/urllib2.py", line 1197, in do_open     raise URLError(err) URLError: 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 04 Jun 2016 19:55:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235550#M26524</guid>
      <dc:creator>tequilalinux</dc:creator>
      <dc:date>2016-06-04T19:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235551#M26525</link>
      <description>&lt;P&gt;Klaxdal,&lt;BR /&gt;
Your answer should really be its own question and answer. It solved my issue with Cisco IPS with Splunk 6.4.  One thing to note is I had to restart Splunk twice for it to start working, the first restart it threw an error, but the second restart it worked.&lt;/P&gt;

&lt;P&gt;Error after first restart&lt;BR /&gt;
    ERROR - Exception thrown in sdee.get(): Traceback (most recent call last):   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/get_ips_feed.py", line 117, in run     sdee.get()   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 211, in get     self._request(params, **kwargs)   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 163, in _request     data = urllib2.urlopen(req)   File "/opt/splunk/lib/python2.7/urllib2.py", line 154, in urlopen     return opener.open(url, data, timeout)   File "/opt/splunk/lib/python2.7/urllib2.py", line 437, in open     response = meth(req, response)   File "/opt/splunk/lib/python2.7/urllib2.py", line 550, in http_response     'http', request, response, code, msg, hdrs)   File "/opt/splunk/lib/python2.7/urllib2.py", line 475, in error     return self._call_chain(*args)   File "/opt/splunk/lib/python2.7/urllib2.py", line 409, in _call_chain     result = func(*args)   File "/opt/splunk/lib/python2.7/urllib2.py", line 558, in http_error_default     raise HTTPError(req.get_full_url(), code, msg, hdrs, fp) HTTPError: HTTP Error 400: Bad Request&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235551#M26525</guid>
      <dc:creator>kmanson</dc:creator>
      <dc:date>2020-09-29T10:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235552#M26526</link>
      <description>&lt;P&gt;Changed to TLSv1 and changed line per your instructions. Worked like a champ! &lt;BR /&gt;
Thanks!!&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 13:05:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235552#M26526</guid>
      <dc:creator>kevinsplunkdotc</dc:creator>
      <dc:date>2016-07-20T13:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add on for Cisco IPS 2.1.5 has error conneting to sensor</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235553#M26527</link>
      <description>&lt;P&gt;Klaxdal's fix works.  Why hasn't it been integrated into the stock TA yet?  It's been almost a year!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 19:05:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Cisco-IPS-2-1-5-has-error-conneting-to-sensor/m-p/235553#M26527</guid>
      <dc:creator>jmantor</dc:creator>
      <dc:date>2018-01-25T19:05:02Z</dc:date>
    </item>
  </channel>
</rss>

