<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk for Cisco IPS - exception thrown in sdee-get() in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Cisco-IPS-exception-thrown-in-sdee-get/m-p/60835#M3664</link>
    <description>&lt;P&gt;I'm setting up Splunk for Cisco IPS for the first time.  It looks like it's able to connect, but seems to not be able to retrieve events.&lt;/P&gt;

&lt;P&gt;sdee_get.log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Fri Aug 19 12:00:41 2011 - INFO - Checking for exsisting SubscriptionID on host: x.x.x.x
Fri Aug 19 12:00:41 2011 - INFO - SubscriptionID: sub-3-adf9579a found for host: x.x.x.x
Fri Aug 19 12:00:41 2011 - INFO - Attempting to connect to sensor: x.x.x.x
Fri Aug 19 12:00:41 2011 - INFO - Successfully connected to: x.x.x.x
Fri Aug 19 12:00:41 2011 - ERROR - Exception thrown in sdee.get(): HTTPError: HTTP Error 400: Bad Request
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The IDS model is ASA_SSM-10.&lt;/P&gt;

&lt;P&gt;Suggestions?&lt;/P&gt;</description>
    <pubDate>Fri, 19 Aug 2011 16:45:08 GMT</pubDate>
    <dc:creator>crob6281</dc:creator>
    <dc:date>2011-08-19T16:45:08Z</dc:date>
    <item>
      <title>Splunk for Cisco IPS - exception thrown in sdee-get()</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Cisco-IPS-exception-thrown-in-sdee-get/m-p/60835#M3664</link>
      <description>&lt;P&gt;I'm setting up Splunk for Cisco IPS for the first time.  It looks like it's able to connect, but seems to not be able to retrieve events.&lt;/P&gt;

&lt;P&gt;sdee_get.log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Fri Aug 19 12:00:41 2011 - INFO - Checking for exsisting SubscriptionID on host: x.x.x.x
Fri Aug 19 12:00:41 2011 - INFO - SubscriptionID: sub-3-adf9579a found for host: x.x.x.x
Fri Aug 19 12:00:41 2011 - INFO - Attempting to connect to sensor: x.x.x.x
Fri Aug 19 12:00:41 2011 - INFO - Successfully connected to: x.x.x.x
Fri Aug 19 12:00:41 2011 - ERROR - Exception thrown in sdee.get(): HTTPError: HTTP Error 400: Bad Request
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The IDS model is ASA_SSM-10.&lt;/P&gt;

&lt;P&gt;Suggestions?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2011 16:45:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Cisco-IPS-exception-thrown-in-sdee-get/m-p/60835#M3664</guid>
      <dc:creator>crob6281</dc:creator>
      <dc:date>2011-08-19T16:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Cisco IPS - exception thrown in sdee-get()</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Cisco-IPS-exception-thrown-in-sdee-get/m-p/60836#M3665</link>
      <description>&lt;P&gt;This error happens when the subscription id for some reason is no longer valid on the device end. You need to delete your x.x.x.x.run file(s) and allow the script to attempt to open a new session without an existing subscription id.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2011 06:20:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Cisco-IPS-exception-thrown-in-sdee-get/m-p/60836#M3665</guid>
      <dc:creator>kenson</dc:creator>
      <dc:date>2011-12-09T06:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Cisco IPS - exception thrown in sdee-get()</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Cisco-IPS-exception-thrown-in-sdee-get/m-p/60837#M3666</link>
      <description>&lt;P&gt;how do you "delete your x.x.x.x.run file(s)"? What subscription ID is this referring too?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2012 14:46:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Cisco-IPS-exception-thrown-in-sdee-get/m-p/60837#M3666</guid>
      <dc:creator>asrozar</dc:creator>
      <dc:date>2012-07-11T14:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Cisco IPS - exception thrown in sdee-get()</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Cisco-IPS-exception-thrown-in-sdee-get/m-p/60838#M3667</link>
      <description>&lt;P&gt;Just stop the script and rm the *.run files in the apps var/run directory. Then start it again. The subscription id refers to some internal mechanism that supposedly helps the ips to remember which events you already fetched..&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2012 08:45:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Cisco-IPS-exception-thrown-in-sdee-get/m-p/60838#M3667</guid>
      <dc:creator>kenson</dc:creator>
      <dc:date>2012-07-31T08:45:48Z</dc:date>
    </item>
  </channel>
</rss>

