I have upgraded to Cisco Security Suite 3.0 and Splunk 6. It appears that the IPS module is not working any more. It did work with the older versions. I am getting an error " The Lookup table 'Cisco_ips_category' does not exist. It is referenced by the configuration 'cisco_ips_syslog'"
I must have missed something in the upgrade process.
Did you figure your issue out? I just upgraded to Splunk 6 and Cisco Security Suite. My assumption was that IPS was integrated into the suite, but it looks like they only have a TA for ASA, WSA, and ISE.
I have not figured out this issue. I did read in some of the documuntation that IPS is slated for a future release.
I am having the exact same issue
Having the same issue as well ! I wish they would fix this back put the IPS information back into the Cisco Security Suite .