How to pull data from Cisco IPS into Splunk. I tried using SDEE pool query but it did not work.
Any help on this would be great.
(for customer kiqbal @ Sega)
You can use the app mentioned by alacercogiltatus. Take note that the app only works for Splunk version 5 and below. So, if you have Splunk 6, this app will not work out of the box. You can use a Splunk 5.x Heavy Forwarder to get information from your IPS and then forward to a Splunk 6 indexer. Or, this thread has a potential workaround for you as well to use IPS with Splunk 6 -> http://answers.splunk.com/answers/105193/cisco-ips-error-errno-8?page=1&focusedAnswerId=135759#13575...
It's old and outdated, but might work: http://apps.splunk.com/app/528/
If this answered your question, please accept it. Thanks!