Getting Data In

IPS stops polling

andy66
New Member

Hi,

First off I want to say great app. Second I want to let you know that I'm new to Splunk and would real like some help.

I installed splunk, cisco secuirty suite and the IPS app. I've been able to configure my IPS devices and create alerts.

The problem I'm running into is that after splunk is running for a bit it appears to stop collecting IPS information and I"m not sure why. I have a screen shot here.

http://www.users.cloud9.net/~andy/splunk_ips.jpg

As you can see I restarted splunk at ~9 am and it looks like it ran for maybe 15 minutes and then stops collecting.

Any help you can give would be great.

I do have another question. It is in regards to the ID/PW being stored in clear text. Is there any way this information could be encrypted. I noticed this in the configuration file as well as the splunk logs.

Thanks,

Andy

Tags (1)
0 Karma

raziasaduddin
Path Finder

This has finally been fixed in the new version of the app. No more cleartext Usernames and Passwords. We requested this, worked with an engineer, and it was fixed.

0 Karma

houstonh
Engager

Not an answer, but I would like to bring up that both items mentioned are still an issue.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...