Getting Data In

Setting up Cisco IPS Sensors

cgekoski
Path Finder

I recently downloaded and setting up splunk for a POC and we would like to include our Cisco IPS Sensors which use SDEE. I have found forums related to setup via old splunk versions and cannot seem to find a valid working IPS App or configuration guide with Splunk6. Any assistance to configuring this or getting the logs into splunk would be appreciated.

Thanks

Cory

Tags (3)
0 Karma

dkuk
Path Finder

There isn't a v6 version yet but it's apparently on its way, I asked the same question a while back - the Cisco Security Suite is gradually being v6'd! Great news.

See this post

For the time being the v5 version will actually grab the logs for you with v6 Splunk still (I've tried this). You just may find that some elements of the shipped dashboards don't look as good as they would in v5 due to version differences.

Deprecated Cisco IPS App Download

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...