<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco IPS app not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85897#M17854</link>
    <description>&lt;P&gt;Really need your help!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Nov 2013 09:28:26 GMT</pubDate>
    <dc:creator>evgenyp</dc:creator>
    <dc:date>2013-11-11T09:28:26Z</dc:date>
    <item>
      <title>Cisco IPS app not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85893#M17850</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;I have issue to make work the Cisco IPS app under splunk.&lt;/P&gt;

&lt;P&gt;I made it works the first time indexing correctly the IPS logs.&lt;BR /&gt;
I did a lot of register script under the set up menu on the Cisco IPS.&lt;BR /&gt;
I tried to delete the wrong one but i was unable to do it because i did get an error message everytime.&lt;BR /&gt;
So i decided to uninstall the app by removing the Splunk_CiscoIPS folder under $SPLUNK/etc/apps/ and restart splunk to make a fresh install.&lt;BR /&gt;
I'd also deleted the CiscoIPS folder I founded under $SPLUNK/etc/users/%user%/&lt;/P&gt;

&lt;P&gt;I made a fresh install and now i'm unable to get the IPS events after doing the set up.&lt;/P&gt;

&lt;P&gt;Here's the log i have in $SPLUNK/var/log/splunk/sdee_get.log&lt;BR /&gt;
    Wed Oct 10 15:00:22 2012 - INFO - No exsisting SubscriptionID for host: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:00:22 2012 - INFO - Attempting to connect to sensor: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:00:22 2012 - INFO - Successfully connected to: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:00:22 2012 - INFO - Checking for exsisting SubscriptionID on host: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:00:22 2012 - INFO - No exsisting SubscriptionID for host: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:00:22 2012 - INFO - Attempting to connect to sensor: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:00:22 2012 - INFO - Successfully connected to: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:00:23 2012 - ERROR - Connecting to sensor - 1.2.3.4: HTTPError: HTTP Error 401: Unauthorized&lt;BR /&gt;
    Wed Oct 10 15:00:24 2012 - ERROR - Connecting to sensor - 1.2.3.4: HTTPError: HTTP Error 400: Bad Request&lt;BR /&gt;
    Wed Oct 10 15:05:23 2012 - INFO - Checking for exsisting SubscriptionID on host: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:05:23 2012 - INFO - No exsisting SubscriptionID for host: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:05:23 2012 - INFO - Attempting to connect to sensor: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:05:23 2012 - INFO - Successfully connected to: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:05:24 2012 - ERROR - Connecting to sensor - 1.2.3.4: HTTPError: HTTP Error 401: Unauthorized&lt;BR /&gt;
    Wed Oct 10 15:05:25 2012 - INFO - Checking for exsisting SubscriptionID on host: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:05:25 2012 - INFO - No exsisting SubscriptionID for host: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:05:25 2012 - INFO - Attempting to connect to sensor: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:05:25 2012 - INFO - Successfully connected to: 1.2.3.4&lt;BR /&gt;
    Wed Oct 10 15:05:26 2012 - ERROR - Connecting to sensor - 1.2.3.4: HTTPError: HTTP Error 400: Bad Request&lt;/P&gt;

&lt;P&gt;It seems to be my credentials which aren't correct but i'd already tried to make another account unsuccessfully.&lt;/P&gt;

&lt;P&gt;Do you have any idea ?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2012 13:20:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85893#M17850</guid>
      <dc:creator>rbw78</dc:creator>
      <dc:date>2012-10-10T13:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IPS app not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85894#M17851</link>
      <description>&lt;P&gt;Up, i really need some help on it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2012 15:16:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85894#M17851</guid>
      <dc:creator>rbw78</dc:creator>
      <dc:date>2012-10-10T15:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IPS app not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85895#M17852</link>
      <description>&lt;P&gt;When you initially setup the app and added the IPS sensors, it created a subscription on the sensor and put the subscription information in the $SPLUNK_HOME\etc\apps\Splunk_CiscoIPS\var\run directory. There should be one file for each sensor named Sensor_IP.run. When you deleted the app and re-installed it and tried to re-add the sensors, it tried to re-setup a new subscription. But, the IPS sensor knew that there was already a subscription created and does not want to create another. There are three ways to fix this:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Go back to the original copy of the IPS app (hopefully you still have it in a recycle bin) and put the run files back into $SPLUNK_HOME\etc\apps\Splunk_CiscoIPS\var\run. You only need the run file(s), nothing else. Make sure you stop Splunk before overwriting them with the old files and then start it back up again.&lt;/LI&gt;
&lt;LI&gt;Login into the IPS sensor via the command line and delete the subscriptions created earlier. First do a "show statistics sdee-server" to view the existing SDEE subscriptions. Find the old one from before and then navigate to &lt;A href="https://Sensor_IP/cgi-bin/sdee-server/?action=close&amp;amp;subscriptionId=SUB_ID" target="_blank"&gt;https://Sensor_IP/cgi-bin/sdee-server/?action=close&amp;amp;subscriptionId=SUB_ID&lt;/A&gt;. For example: &lt;A href="https://10.1.1.1/cgi-bin/sdee-server/?action=close&amp;amp;subscriptionId=sub-16-a64a8e10" target="_blank"&gt;https://10.1.1.1/cgi-bin/sdee-server/?action=close&amp;amp;subscriptionId=sub-16-a64a8e10&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Wait for a few days. I believe the subscriptions will time out after 7 days. So if you wait they will expire and then it will start working again.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;If that does not work, let me know and there are a few other things we can check on the IPS sensor.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:37:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85895#M17852</guid>
      <dc:creator>andrew_garvin</dc:creator>
      <dc:date>2020-09-28T12:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IPS app not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85896#M17853</link>
      <description>&lt;P&gt;Hello, could you help me with the same situation, one time after PSOD of my esxi where virtual splunk is working, i saw that ips logs stopped to go to the splunk. i updated cisco_ips to 2.0.0 and used the old script for ips in splunk (because with web splunk cisco_ips configuration i'm getting the following error:&lt;/P&gt;

&lt;P&gt;Encountered the following error while trying to update: In handler 'localapps': Error while posting to url=/servicesNS/nobody/Splunk_CiscoIPS/admin/cisco_ips_setup/cisco_ips_setup_settings&lt;/P&gt;

&lt;P&gt;then i just changed configured to 1)&lt;/P&gt;

&lt;P&gt;in Cisco IPS sensor:&lt;/P&gt;

&lt;P&gt;ips# sh statistics sdee-server&lt;BR /&gt;
General&lt;BR /&gt;
   Open Subscriptions = 0&lt;BR /&gt;
   Blocked Subscriptions = 0&lt;BR /&gt;
   Maximum Available Subscriptions = 5&lt;BR /&gt;
   Maximum Events Per Retrieval = 500&lt;BR /&gt;
Subscriptions&lt;/P&gt;

&lt;P&gt;On the splunk:&lt;/P&gt;

&lt;P&gt;Sun Nov 10 21:43:32 2013 - INFO - Checking for exsisting SubscriptionID on host: 192.168.1.2&lt;/P&gt;

&lt;P&gt;host = seclog &lt;BR /&gt;
 source = /opt/splunk/var/log/splunk/sdee_get.log &lt;BR /&gt;
 sourcetype = sdee_connection &lt;/P&gt;

&lt;P&gt;Sun Nov 10 21:43:32 2013 - INFO - No exsisting SubscriptionID for host: 192.168.1.2&lt;/P&gt;

&lt;P&gt;host = seclog &lt;BR /&gt;
 source = /opt/splunk/var/log/splunk/sdee_get.log &lt;BR /&gt;
 sourcetype = sdee_connection &lt;/P&gt;

&lt;P&gt;Sun Nov 10 21:43:32 2013 - INFO - Attempting to connect to sensor: 192.168.1.2&lt;/P&gt;

&lt;P&gt;host = seclog &lt;BR /&gt;
 source = /opt/splunk/var/log/splunk/sdee_get.log &lt;BR /&gt;
 sourcetype = sdee_connection &lt;/P&gt;

&lt;P&gt;Sun Nov 10 21:43:32 2013 - INFO - Successfully connected to: 192.168.1.2&lt;/P&gt;

&lt;P&gt;host = seclog &lt;BR /&gt;
 source = /opt/splunk/var/log/splunk/sdee_get.log &lt;BR /&gt;
 sourcetype = sdee_connection &lt;/P&gt;

&lt;P&gt;Sun Nov 10 21:43:32 2013 - ERROR - Connecting to sensor - 192.168.1.2: URLError: &lt;URLOPEN error=""&gt;&lt;/URLOPEN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:14:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85896#M17853</guid>
      <dc:creator>evgenyp</dc:creator>
      <dc:date>2020-09-28T15:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IPS app not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85897#M17854</link>
      <description>&lt;P&gt;Really need your help!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2013 09:28:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85897#M17854</guid>
      <dc:creator>evgenyp</dc:creator>
      <dc:date>2013-11-11T09:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IPS app not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85898#M17855</link>
      <description>&lt;P&gt;That message would seem to indicate that the Splunk server cannot connect to the IPS. I think you need to start with the basics. Can you ping the IPS from the Splunk server? Can you navigate to &lt;A href="https://Sensor_IP/cgi-bin/sdee-server"&gt;https://Sensor_IP/cgi-bin/sdee-server&lt;/A&gt; from the Splunk server?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2013 04:45:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85898#M17855</guid>
      <dc:creator>andrew_garvin</dc:creator>
      <dc:date>2013-11-18T04:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IPS app not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85899#M17856</link>
      <description>&lt;P&gt;Yes, i can do ping, get https from ips it seems that it is ok everything and that was working during year, but after that psod, everything stopped. think maybe i should to reboot the asa IPS module i already rebooted.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2013 11:58:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cisco-IPS-app-not-working/m-p/85899#M17856</guid>
      <dc:creator>evgenyp</dc:creator>
      <dc:date>2013-11-18T11:58:04Z</dc:date>
    </item>
  </channel>
</rss>

