Hello,
I have installed Cisco TA 2.1.6 on HFW and trying to get logs from CISCO IPS devices.
I have configured the settings under inputs.conf :
[script://$SPLUNK_HOME/etc/apps/Splunk_CiscoIPS/bin/get_ips_feed.py ]
sourcetype = cisco_ips_syslog
source = SDEE
disabled = false
interval = 1
I don't see any logs under - sensor_ip.run
I execute this as per troubleshooting docs-
index="_internal" sourcetype="sdee_connection" ERROR | rex "Connecting to sensor - (?[^:]+)" | rex "[Errno\s+(?[^]]+)" | stats count values(EN) as error_number by sensor
error_number= 110
when I run -
index="_internal" sourcetype="sdee_connection"
on Mar 5 21:37:35 2018 - ERROR - Connecting to sensor - X.XX.XXX.X: Traceback (most recent call last): File "/data/splunk/etc/apps/Splunk_TA_cisco-ips/bin/get_ips_feed.py", line 103, in run sdee.open() File "/data/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 191, in open self._request(params) File "/data/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 167, in _request data = urllib2.urlopen(req) File "/data/splunk/lib/python2.7/urllib2.py", line 154, in urlopen return opener.open(url, data, timeout) File "/data/splunk/lib/python2.7/urllib2.py", line 429, in open response = self._open(req, data) File "/data/splunk/lib/python2.7/urllib2.py", line 447, in _open '_open', req) File "/data/splunk/lib/python2.7/urllib2.py", line 407, in _call_chain result = func(*args) File "/data/splunk/lib/python2.7/urllib2.py", line 1241, in https_open context=self._context) File "/data/splunk/lib/python2.7/urllib2.py", line 1198, in do_open raise URLError(err) URLError:
Also tried - wget https://X.X.X.X/cgi-bin/sdee-server/
--2018-03-05 21:06:17-- https://X.X.X.X/cgi-bin/sdee-server/
Connecting to X.X.X.X:443... failed: Connection timed out.
Retrying.
Please suggest
... View more