Hi,
I have Splunk 6.2.3 and the Splunk Add-on for Cisco IPS 2.1.3 and I cannot get the IPS added. When I try and add it, Splunk shows:
Encountered the following error while trying to update: In handler 'localapps': Error while posting to url=/servicesNS/nobody/Splunk_TA_cisco-ips/admin/cisco_ips_setup/cisco_ips_setup_settings
I have tried the various workarounds posted about changing TLS/SSL, but no joy. I saw one mention of the IPS version, ours is 7.1 should this work?
Thanks,
Might need to add "edit-scripted" capability to the Role you are doing this with.
Any joy on this issue so far?
From my point of view, this is the app problem couldn't update setting after first set.
If you go file system and remove these files, restarted Splunk. Then you can reset/correct IP, credentials with the error.
$SPLUNK_HOME/etc/apps/Splunk_TA_cisco-ips/local
app.conf
inputs.conf
passwords.conf
I had the same error, but mine was just file permissions. Changed the app's owner:group to splunk and the was able to save successfully.
This sort of thing is usually about REST connections between the browser and Splunk... diagnosing what the problem is requires some knowledge of platform and environment. You should probably open a support case.
Ok, thanks I'll do that. I did update the IPS add-on 2.1.4 but am still seeing the same.
The troubleshooting guide is here: http://docs.splunk.com/Documentation/AddOns/latest/CiscoIPS/Troubleshooting