I have Splunk 6.2.3 and the Splunk Add-on for Cisco IPS 2.1.3 and I cannot get the IPS added. When I try and add it, Splunk shows:
Encountered the following error while trying to update: In handler 'localapps': Error while posting to url=/servicesNS/nobody/Splunk_TA_cisco-ips/admin/cisco_ips_setup/cisco_ips_setup_settings
I have tried the various workarounds posted about changing TLS/SSL, but no joy. I saw one mention of the IPS version, ours is 7.1 should this work?
From my point of view, this is the app problem couldn't update setting after first set.
If you go file system and remove these files, restarted Splunk. Then you can reset/correct IP, credentials with the error.
This sort of thing is usually about REST connections between the browser and Splunk... diagnosing what the problem is requires some knowledge of platform and environment. You should probably open a support case.