<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco IPS Connecting error in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100762#M1456</link>
    <description>&lt;P&gt;Another problem that can cause this is over-subscribed devices. IPS devices generally have a default subscription limit of 5. Here is one &lt;A href="https://supportforums.cisco.com/document/47881/sdee-and-ips"&gt;article that details enumerating sessions&lt;/A&gt;. We've seen this happen both from stale subscriptions and separately other teams/technologies polling the IPS device.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Apr 2015 13:14:58 GMT</pubDate>
    <dc:creator>bwooden</dc:creator>
    <dc:date>2015-04-07T13:14:58Z</dc:date>
    <item>
      <title>Cisco IPS Connecting error</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100756#M1450</link>
      <description>&lt;P&gt;I can access the IPS without issue through Cisco IPS Manager Express (IME) and can connect to the IPS from telnet. But why I get this error? &lt;/P&gt;

&lt;P&gt;sdee_get.log :&lt;/P&gt;

&lt;P&gt;Wed Oct 24 14:53:10 2012 - INFO - Checking for exsisting SubscriptionID on host: 10.42.12.20&lt;BR /&gt;
Wed Oct 24 14:53:10 2012 - INFO - No exsisting SubscriptionID for host: 10.42.12.20&lt;BR /&gt;
Wed Oct 24 14:53:10 2012 - INFO - Attempting to connect to sensor: 10.42.12.20&lt;BR /&gt;
Wed Oct 24 14:53:10 2012 - INFO - Successfully connected to: 10.42.12.20&lt;BR /&gt;
Wed Oct 24 14:53:11 2012 - ERROR - Connecting to sensor - 10.42.12.20: URLError: urlopen error [Errno 10061] No connection could be made because the target machine actively refused it&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 08:00:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100756#M1450</guid>
      <dc:creator>dx50</dc:creator>
      <dc:date>2012-10-24T08:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IPS Connecting error</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100757#M1451</link>
      <description>&lt;P&gt;I believe that you have to allow the IP that the script is running from to connect to the IPS somewhere in the IME. That is, the sensor needs to be told to allow connections from the Splunk box. Wish I could tell you where in the config.&lt;/P&gt;

&lt;P&gt;HTH,&lt;/P&gt;

&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 14:48:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100757#M1451</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2012-10-24T14:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IPS Connecting error</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100758#M1452</link>
      <description>&lt;P&gt;I agree with Dave. Make sure you can ping and make https connections to the IPS appliance from the Splunk server. If you confirm connectivity and you are still having an issue, please let us know.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 17:44:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100758#M1452</guid>
      <dc:creator>andrew_garvin</dc:creator>
      <dc:date>2012-10-25T17:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IPS Connecting error</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100759#M1453</link>
      <description>&lt;P&gt;This is a late response but thought I'd post it for others that might be experiencing the same problem.&lt;/P&gt;

&lt;P&gt;You have to permit the Splunk box to connect on the IPS device.  You can do this by re-running the setup from the command line or by clicking Sensor Setup &amp;gt; Allowed Hosts/Networks &amp;gt; Add in IME or IDM.&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2014 16:14:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100759#M1453</guid>
      <dc:creator>strumpowertsc</dc:creator>
      <dc:date>2014-05-05T16:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IPS Connecting error</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100760#M1454</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have a similar problem and the splunk is in the Allowed host, I can ping the IPS and get de XML with no problem from the splunk.&lt;/P&gt;

&lt;P&gt;Mon Feb 23 13:03:07 2015 - INFO - Checking for exsisting SubscriptionID on host: 10.201.158.23&lt;BR /&gt;
Mon Feb 23 13:03:07 2015 - INFO - No exsisting SubscriptionID for host: 10.201.158.23&lt;BR /&gt;
Mon Feb 23 13:03:07 2015 - INFO - Attempting to connect to sensor: 10.201.158.23&lt;BR /&gt;
Mon Feb 23 13:03:07 2015 - INFO - Successfully connected to: 10.201.158.23&lt;BR /&gt;
Mon Feb 23 13:03:08 2015 - ERROR - Connecting to sensor - 10.201.158.23: URLError: urlopen error [Errno 104] Connection reset by peer&amp;gt;&lt;/P&gt;

&lt;P&gt;What can it be?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2015 16:20:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100760#M1454</guid>
      <dc:creator>paguayof</dc:creator>
      <dc:date>2015-02-23T16:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IPS Connecting error</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100761#M1455</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;

&lt;P&gt;Modifying the &lt;STRONG&gt;bin/pysdee/pySDEE.py&lt;/STRONG&gt; and changing the SSLv3 version to TLSv1 helped solve my problem, as was explained here&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/105193/cisco-ips-error-errno-8.html"&gt;http://answers.splunk.com/answers/105193/cisco-ips-error-errno-8.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;and here: &lt;/P&gt;

&lt;P&gt;&lt;A href="http://blog.hortonew.com/splunk-ciscoips-app-no-longer-pulls-from-ips"&gt;http://blog.hortonew.com/splunk-ciscoips-app-no-longer-pulls-from-ips&lt;/A&gt;&lt;BR /&gt;
Hope it helps you, too&lt;/P&gt;

&lt;P&gt;I.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2015 12:41:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100761#M1455</guid>
      <dc:creator>ilirb</dc:creator>
      <dc:date>2015-04-07T12:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IPS Connecting error</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100762#M1456</link>
      <description>&lt;P&gt;Another problem that can cause this is over-subscribed devices. IPS devices generally have a default subscription limit of 5. Here is one &lt;A href="https://supportforums.cisco.com/document/47881/sdee-and-ips"&gt;article that details enumerating sessions&lt;/A&gt;. We've seen this happen both from stale subscriptions and separately other teams/technologies polling the IPS device.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2015 13:14:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Cisco-IPS-Connecting-error/m-p/100762#M1456</guid>
      <dc:creator>bwooden</dc:creator>
      <dc:date>2015-04-07T13:14:58Z</dc:date>
    </item>
  </channel>
</rss>

