I've "configured" the Splunk for Cisco IPS application, but I'm getting the following back from the scripted input:
Thu Feb 7 12:36:24 2013 - INFO - Checking for exsisting SubscriptionID on host: x.x.x.x
Thu Feb 7 12:36:24 2013 - INFO - No exsisting SubscriptionID for host: x.x.x.x
Thu Feb 7 12:36:24 2013 - INFO - Attempting to connect to sensor: x.x.x.x
Thu Feb 7 12:36:24 2013 - INFO - Successfully connected to: x.x.x.x
Thu Feb 7 12:37:39 2013 - ERROR - Connecting to sensor - x.x.x.x: URLError:
What does URL Error 104 mean
Did you ever get this fixed?
If not, what version of the IPS app are you running? Can you ping the IPS from the Splunk server? Can you access https://Sensor_IP/cgi-bin/sdee-server from the Splunk server? What version of the Cisco IPS software are you running?