Refine your search:

Thanks For Downloading!

Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows:

Windows: Decompress the downloaded file using a tool like 7-Zip and place the resulting folder into %PROGRAMFILES%\Splunk\etc\apps. Then restart Splunk using the splunk restart command or the GUI.

Unix/Linux: Decompress the downloaded file using a tool like tar -xvf and place the resulting folder into $SPLUNK_HOME/etc/apps. Then restart Splunk using the splunk restart command or the GUI.

Description

The Splunk for Cisco IPS technology add-on is a collection of scripted inputs, field extractions, and other search-time knowledge that is used to drive reporting and search for data collected from Cisco IPS devices. The scripted input included in this add-on can be configured to collect data from Cisco IPS sensors using the Security Device Event Exchange (SDEE) format.

Security Device Event Exchange (SDEE) is a standard proposed by ICSA that specifies the format of messages and protocol used to communicate events generated by security devices. This protocol is used in the Cisco IPS Sensor 5.0 software to replace Remote Data Exchange Protocol (RDEP), which is used by earlier versions of the Cisco IDS Sensor software. The IPS data format is XML. Splunk for SDEE translates and maps the data into key value pairs.

This add-on can be used standalone, or it can be installed with the Cisco Security Suite umbrella app and other Cisco Security Suite apps and add-ons to provide a single pane of glass interface and get out of box reports on Cisco firewall devices and other Cisco technology data.

Important note: This add-on, under its new name, Splunk for Cisco IPS, replaces the older and very popular Cisco IPS SDEE Data Collector and contains all of the functionality of its predecessor plus the enhancements listed in the release notes below.

Additional information and download for Cisco Security Suite can be found on Splunkbase. The other Cisco Security Suite apps and add-ons include:

Installation and configuration instructions for this add-on can be found in the README file within the downloaded package.

Versions and Release Notes

Version 2.0.0 (current version - updated Jan 25, 2013)
release notes:

Reports and dashboards have been removed from the plug-in and placed in the Cisco Security Suite. Please download the Cisco Security Suite for the search head components.

show older versions »
Version 1.0.0 (updated Jan 25, 2013)
release notes:

- Updated to provide compatibility with Splunk 4.2
- Updated to include a new setup workflow to assist with initial configuration

Version 1.1.1 (updated Jul 02, 2012)
release notes:

1.1.1 (2012-06-29)
- Added an additional field passed to get_ips_feed.py that causes the script to wait a specified ammount of time (in seconds) in between polls of the IPS. If the value is not passed, it will default to 15 seconds (for backwards compatibility). If a value of 0 is specified, it will poll continuously (like previous versions).
- Changed date/time stamp in the alert to be a human-readable format. Alert time from the IPS is sent as “time in nanoseconds from 1970-01-01T00:00:00Z”. So, the time showed as a large integer such as 1339900639985884000. Changed to to display as YYYY-MM- DD HH:MM:SS instead.

1.1.0 (2012-05-29)
- Made MARS Category field optional. If IPS provides it, it will be included, if not, it won't. Resolves bug where Splunk for Cisco IPS app crashes on IPS version 7.x.
- Removed redundant protocol entry in output
- Added context field that will be present if IPS device provides it. This is common if running the IPS in a multi-context ASA.
- Changed packet data to remove new-line characters so it will all fit on one line instead of being spread out over many lines. And included the packet data into one big event instead of a separate one.
- Removed isDropped field. Not necessary any more, see next item.
- Added the following values that will be present if the following actions were taken.
ipLoggingActivated
shunRequested
droppedPacket
deniedAttacker
blockConnectionRequested
logAttackerPacketsActivated
logVictimPacketsActivated
logPairPacketsActivated
snmpTrapRequested
deniedAttackerServicePair
deniedAttackerVictimPair
- Added actions field that will contain a comma separated list of all actions taken from list above
- Added summary_count and initial_alert for summary alerts.

Version 1.0.4 (updated Feb 15, 2012)
release notes:

- Added log rotation feature.
- Removed Cisco MARS category.

Version 1.0.4 (updated Feb 15, 2012)
release notes:

- Added log rotation feature.
- Removed Cisco MARS category.

Version 1.0.2 (updated May 21, 2011)
release notes:

Resolved the following issues:
- Cisco IPS get_ips_feed.py script fails on Windows when package extracted using Winzip (SOLN-949)
- Cisco IPS setup fails to configure scripted inputs with appropriate OS path separators (SOLN-925)

Version 1.0.1 (updated Mar 22, 2011)
release notes:

This maintenance release includes a fix for:

Bug SOLN-829 Cisco IPS scripts refer to incorrect folder name "cisco_ips"

See http://answers.splunk.com/questions/12692/app-not-installing-correctly

posted 12 Mar '11, 01:50

splunksolutions's gravatar image

splunksolutions
3.1k12
accept rate: 0%

new version 25 Jan, 16:07


5 Reviews:
5 reviews, 0 ratings, average 0.0

Wrong details being pulled by get_ips_feed.py for 'Signature'. Currently we have the signature field being pulled by sigDetails from the Cisco IPS logs. We should pull signature from Signature --> Description instead. which carry more useful data with respect to Signature for an event.

Can some please help on this.

comments (1)

reviewed 25 Apr, 04:56

bhanu22's gravatar image

bhanu22
1
accept rate: 0%

That is correct. In the Splunk for Cisco IPS App, the 'Signature' field maps to the 'signatureID' and the 'Description' field maps to the 'sigDetails' and the 'signatureDescription' is not being recorded. Is that a problem? How would you like to see it displayed?

(10 May, 16:20) andrew_garvin
Reviews related to version 1.0.0 (current is 2.0.0)

Has anyone got this to work with multiple IPS devices, when I installed; it only asked for 1 ip address, with acct/pw, I have 25 devices, but it doesn't give the option to pull information from more than one device.

comments (1)

reviewed 02 Oct '12, 11:44

tim.bates's gravatar image

tim.bates
11
accept rate: 0%

I haven't personally done it, but if you go to Manger --> Apps, find the Cisco IPS app, and choose setup, it says "You can re-run this setup program at any time from the Splunk Manager to add additional data inputs for other Cisco IPS devices. "

So, it would appear that you would have to run the setup 24 more times to get the rest of your devices set up...

(14 Nov '12, 12:28) djbyler

Hello

Is it possible for SDEE collected logs cto be converted into Syslog format and forwarded to a Syslog server?

comments (0)

reviewed 13 Feb '12, 07:46

samer_ibrahim's gravatar image

samer_ibrahim
212
accept rate: 0%

Has anyone made this and Splunk work together? We're running into many issues and could use a hand. Specifically, this error:

Wed Jan 11 10:23:27 2012 - ERROR - Exception thrown while parsing SDEE payload: Traceback (most recent call last):
  File "C:\Program Files\Splunk\etc\apps\Splunk_CiscoIPS\bin\get_ips_feed.py", line 74, in run
    alert_obj_list = idsmxml.parse_alerts( result_xml )
  File "C:\Program Files\Splunk\etc\apps\Splunk_CiscoIPS\bin\pysdee\idsmxml.py", line 243, in parse_alerts
    alert_obj.signature = build_sig(sig[0])
  File "C:\Program Files\Splunk\etc\apps\Splunk_CiscoIPS\bin\pysdee\idsmxml.py", line 190, in build_sig
    signature.marscategory = node.getElementsByTagName('marsCategory')[0].firstChild.wholeText
IndexError: list index out of range
comments (0)

reviewed 11 Jan '12, 08:21

hortonew's gravatar image

hortonew
6115
accept rate: 0%

Reviews related to version 1.0.4 (current is 2.0.0)

The script get_ips_feed.py runs forever, because of "while 1". So the option "interval" wants to be modify, it seems it can not work.

Thanks for your advice !

comments (0)

reviewed 28 Sep '11, 04:20

ysouchon's gravatar image

ysouchon
3715
accept rate: 25%

Your review

Did you find this app useful?

Preview toggle preview

Copyright © 2005-2012 Splunk Inc. All rights reserved.