All Apps and Add-ons

Splunk Cisco IPS

djames
New Member

When I run | search index="_internal" sourcetype="sdee_connection" I get the following error:

Mon May 16 10:20:10 2011 - ERROR - Exception thrown while parsing SDEE payload: Traceback (most recent call last):
  File "/opt/splunk/etc/apps/Splunk_CiscoIPS/bin/get_ips_feed.py", line 74, in run
    alert_obj_list = idsmxml.parse_alerts( result_xml )
  File "/opt/splunk/etc/apps/Splunk_CiscoIPS/bin/pysdee/idsmxml.py", line 240, in parse_alerts
    alert_obj = build_global(alert)
  File "/opt/splunk/etc/apps/Splunk_CiscoIPS/bin/pysdee/idsmxml.py", line 136, in build_global
    alert.appname = node.getElementsByTagName('sd:originator')[0].getElementsByTagName('cid:appName')[0].firstChild.wholeText
IndexError: list index out of range
0 Karma

troywollenslege
Path Finder

our splunkd.log
failed to parse timestamp for event. context="source::c:\Splunk_CiscoIPS\bin\get_ips_feed.py", line 74 in run...
Failed to parse timestamp for event. Context="soruce::c:\var\log\sdee_get.log|host::ciscohost|sdee_get-too_small|" Text="
failed to parse timestamp for event.
context="source::c:\Splunk_CiscoIPS\bin\pysdee\idsmxml.py", line 243, in parse_..."

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

whats in your splunkd.log? It should have some messages in it which are relevant to the collection of these logs via the scripted input. I know there are people who have this configuration working out there.

0 Karma

djames
New Member

Has anyone ever got this to work? I am trying to see the IPS alerts from my Cisco ISR router running the IOS IPS feature set. I run on the router sh ip sdee sub and can see that the router is sending the sdee alerts to the splunk server. I am running the latest splunk on a 64bit Ubuntu server. But other than that, absolutely nothing on the real time IPS Dashboard.

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

There was an error around this particular 'list index out of range' error that was resolved in 4.2.1, SPL-38100. If you haven't already, it may be a good idea to update the product to see if that resolves this problem.

0 Karma

troywollenslege
Path Finder

We are getting the same error. Running on 4.2.5 windows forwarder (with forwarder license)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...