All Apps and Add-ons

The Splunk Add-on for Cisco IPS does connect and gather data, but why doesn't data show up in the Search app?

antinym
New Member

Addon v 2.1.4. Splunk v6.2.2 windows 2008 SP2.

Sdee connection is successful, I see good IPS data in the files in my D:\splunk\etc\apps\Splunk_TA_cisco-ips\var\log folder, but I can't see that data in the main search app.

I've done searches for keywords that show up in the log files, "eventtype=cisco_ips", IPs of the IPS's but the data doesn't show up.

0 Karma
1 Solution

bwooden
Splunk Employee
Splunk Employee

Hi @antinym,

It sounds like that Splunk instance is not configured to monitor the output of that directory. Has Splunk been configured to monitor the output? There are steps in the Installation Manual for the IPS Add-On that can help you verify this from UI or CLI.

For windows, via the UI...

  1. Navigate to Settings > Data inputs > Files & directories. Click Enable for the IPS monitor statement that matches your OS. For Windows that is $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-ips\var\log\ips_sdee.log*

View solution in original post

bwooden
Splunk Employee
Splunk Employee

Hi @antinym,

It sounds like that Splunk instance is not configured to monitor the output of that directory. Has Splunk been configured to monitor the output? There are steps in the Installation Manual for the IPS Add-On that can help you verify this from UI or CLI.

For windows, via the UI...

  1. Navigate to Settings > Data inputs > Files & directories. Click Enable for the IPS monitor statement that matches your OS. For Windows that is $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-ips\var\log\ips_sdee.log*

antinym
New Member

That was it.
I had enabled the *nix directory for monitoring not the Windows one.
Thanks a thousand.

0 Karma
Get Updates on the Splunk Community!

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...