Hi,
First off I want to say great app. Second I want to let you know that I'm new to Splunk and would real like some help.
I installed splunk, cisco secuirty suite and the IPS app. I've been able to configure my IPS devices and create alerts.
The problem I'm running into is that after splunk is running for a bit it appears to stop collecting IPS information and I"m not sure why. I have a screen shot here.
http://www.users.cloud9.net/~andy/splunk_ips.jpg
As you can see I restarted splunk at ~9 am and it looks like it ran for maybe 15 minutes and then stops collecting.
Any help you can give would be great.
I do have another question. It is in regards to the ID/PW being stored in clear text. Is there any way this information could be encrypted. I noticed this in the configuration file as well as the splunk logs.
Thanks,
Andy
... View more