I added Splunk_CiscoSecuritySuite 1.0.1 today.
There is an error on the top of the Cisco SecuritySuite web:
"Error in 'lookup' command: The lookup table 'geoip' does not exist."
"Unable to find an eventtype ironport*"
How to resolve?
Anyone have any experience with this error? I have the exact same thing.
I installed the apps Cisco Ironport Web Security Appliance and MAXMIND. That solved the problem for me.
install apps Geo Localisation