Getting Data In

Setting up Cisco IPS Sensors

cgekoski
Path Finder

I recently downloaded and setting up splunk for a POC and we would like to include our Cisco IPS Sensors which use SDEE. I have found forums related to setup via old splunk versions and cannot seem to find a valid working IPS App or configuration guide with Splunk6. Any assistance to configuring this or getting the logs into splunk would be appreciated.

Thanks

Cory

Tags (3)
0 Karma

dkuk
Path Finder

There isn't a v6 version yet but it's apparently on its way, I asked the same question a while back - the Cisco Security Suite is gradually being v6'd! Great news.

See this post

For the time being the v5 version will actually grab the logs for you with v6 Splunk still (I've tried this). You just may find that some elements of the shipped dashboards don't look as good as they would in v5 due to version differences.

Deprecated Cisco IPS App Download

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...