I had it working, barely. One IPS module was reporting even though I had six I was trying to get data from. So I installed an update that appeared in the manager and that broke the app completely. I deleted the app folder and restarted Splunk, then I tried a fresh install of the app. Now I get a message that says the app is awaiting setup. I click the setup link and am prompted for the ip and credentials to add the sensor. When I enter the information and click save, I get this message.
Encountered the following error while trying to update: In handler 'localapps': Failed to search for existing Cisco IPS Sensor credential in app.conf!
I've no idea what this means. I hope somebody can help me.
Where is local/app.conf?
The server is Ubuntu.
What operating system are you running on your Splunk server?
I tried to reproduce the error myself, but I can't. I tried removing and readding the app several different ways, but it worked every time. Here are a few things you can try.
Sorry, I meant $SPLUNK_HOME\etc\apps\Splunk_CiscoIPS\local\app.conf
Where is local/app.conf?
The server is Ubuntu.