Getting Data In

Setting up Cisco IPS Sensors

cgekoski
Path Finder

I recently downloaded and setting up splunk for a POC and we would like to include our Cisco IPS Sensors which use SDEE. I have found forums related to setup via old splunk versions and cannot seem to find a valid working IPS App or configuration guide with Splunk6. Any assistance to configuring this or getting the logs into splunk would be appreciated.

Thanks

Cory

Tags (3)
0 Karma

dkuk
Path Finder

There isn't a v6 version yet but it's apparently on its way, I asked the same question a while back - the Cisco Security Suite is gradually being v6'd! Great news.

See this post

For the time being the v5 version will actually grab the logs for you with v6 Splunk still (I've tried this). You just may find that some elements of the shipped dashboards don't look as good as they would in v5 due to version differences.

Deprecated Cisco IPS App Download

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...