<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem  mionitor cisco IPS in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Problem-mionitor-cisco-IPS/m-p/51179#M7010</link>
    <description>&lt;P&gt;We were recently made aware of this issue caused by an un-annouced change in the SDEE payload with the latest software update. We will be pushing a fix to Splunkbase soon but in the mean time please feel free to contact me directly and I will send you an update. You can reach me at: will (at) splunk.com&lt;BR /&gt;
Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 08 Feb 2012 20:14:01 GMT</pubDate>
    <dc:creator>Will_Hayes</dc:creator>
    <dc:date>2012-02-08T20:14:01Z</dc:date>
    <item>
      <title>Problem  mionitor cisco IPS</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Problem-mionitor-cisco-IPS/m-p/51177#M7008</link>
      <description>&lt;P&gt;I have a problem to monitor the module Cisco IPS ASA5585-SSP-IPS10&lt;/P&gt;

&lt;P&gt;From the IPS I see this error ; the state remain in state Read Pending;&lt;/P&gt;

&lt;P&gt;sub-8-9480fcb4&lt;BR /&gt;
      State = Read Pending&lt;BR /&gt;
      Last Read Time = 13:22:42 UTC Mon Aug 01 2011&lt;BR /&gt;
      Last Read Time (nanoseconds) = 1312204962229391000&lt;/P&gt;

&lt;P&gt;From the splunk server I see this error:&lt;/P&gt;

&lt;P&gt;tail -f  /opt/splunk/var/log/splunk/sdee_get.log&lt;/P&gt;

&lt;P&gt;Fri Jul 29 14:26:45 2011 - ERROR - Exception thrown while parsing SDEE payload: Traceback (most recent call last):&lt;BR /&gt;
File "/opt/splunk/etc/apps/Splunk_CiscoIPS/bin/get_ips_feed.py", line 74, in run&lt;BR /&gt;
alert_obj_list = idsmxml.parse_alerts( result_xml )&lt;BR /&gt;
File "/opt/splunk/etc/apps/Splunk_CiscoIPS/bin/pysdee/idsmxml.py", &lt;BR /&gt;
line 243, in parse_alerts alert_obj.signature = build_sig(sig[0])&lt;BR /&gt;
File "/opt/splunk/etc/apps/Splunk_CiscoIPS/bin/pysdee/idsmxml.py", line 190, in build_sig&lt;BR /&gt;
signature.marscategory = node.getElementsByTagName('marsCategory')[0].firstChild.wholeText&lt;BR /&gt;
IndexError: list index out of range&lt;/P&gt;

&lt;P&gt;There's a solution to resolve this problem?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:46:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Problem-mionitor-cisco-IPS/m-p/51177#M7008</guid>
      <dc:creator>mbattaglia</dc:creator>
      <dc:date>2020-09-28T09:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Problem  mionitor cisco IPS</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Problem-mionitor-cisco-IPS/m-p/51178#M7009</link>
      <description>&lt;P&gt;we are getting the same error, did you find a solution?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2012 18:55:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Problem-mionitor-cisco-IPS/m-p/51178#M7009</guid>
      <dc:creator>troywollenslege</dc:creator>
      <dc:date>2012-02-03T18:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problem  mionitor cisco IPS</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Problem-mionitor-cisco-IPS/m-p/51179#M7010</link>
      <description>&lt;P&gt;We were recently made aware of this issue caused by an un-annouced change in the SDEE payload with the latest software update. We will be pushing a fix to Splunkbase soon but in the mean time please feel free to contact me directly and I will send you an update. You can reach me at: will (at) splunk.com&lt;BR /&gt;
Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2012 20:14:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Problem-mionitor-cisco-IPS/m-p/51179#M7010</guid>
      <dc:creator>Will_Hayes</dc:creator>
      <dc:date>2012-02-08T20:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Problem  mionitor cisco IPS</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Problem-mionitor-cisco-IPS/m-p/51180#M7011</link>
      <description>&lt;P&gt;Please update the Cisco IPS apps to latest version, it should fix the error. &lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2012 08:35:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Problem-mionitor-cisco-IPS/m-p/51180#M7011</guid>
      <dc:creator>mwong</dc:creator>
      <dc:date>2012-05-08T08:35:23Z</dc:date>
    </item>
  </channel>
</rss>

