Getting Data In

Setting up Cisco IPS Sensors

cgekoski
Path Finder

I recently downloaded and setting up splunk for a POC and we would like to include our Cisco IPS Sensors which use SDEE. I have found forums related to setup via old splunk versions and cannot seem to find a valid working IPS App or configuration guide with Splunk6. Any assistance to configuring this or getting the logs into splunk would be appreciated.

Thanks

Cory

Tags (3)
0 Karma

dkuk
Path Finder

There isn't a v6 version yet but it's apparently on its way, I asked the same question a while back - the Cisco Security Suite is gradually being v6'd! Great news.

See this post

For the time being the v5 version will actually grab the logs for you with v6 Splunk still (I've tried this). You just may find that some elements of the shipped dashboards don't look as good as they would in v5 due to version differences.

Deprecated Cisco IPS App Download

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...