All Apps and Add-ons

Splunk Add-on for Cisco IPS 2.1.3 and Splunk 6.2.3: Why am I getting an error when adding a device?

mduckett
Engager

Hi,

I have Splunk 6.2.3 and the Splunk Add-on for Cisco IPS 2.1.3 and I cannot get the IPS added. When I try and add it, Splunk shows:

Encountered the following error while trying to update: In handler 'localapps': Error while posting to url=/servicesNS/nobody/Splunk_TA_cisco-ips/admin/cisco_ips_setup/cisco_ips_setup_settings

I have tried the various workarounds posted about changing TLS/SSL, but no joy. I saw one mention of the IPS version, ours is 7.1 should this work?

Thanks,

agadayev
Path Finder

Might need to add "edit-scripted" capability to the Role you are doing this with.

0 Karma

bbiandov
Path Finder

Any joy on this issue so far?

0 Karma

hochit
Path Finder

From my point of view, this is the app problem couldn't update setting after first set.
If you go file system and remove these files, restarted Splunk. Then you can reset/correct IP, credentials with the error.

$SPLUNK_HOME/etc/apps/Splunk_TA_cisco-ips/local
app.conf

inputs.conf

passwords.conf

0 Karma

kmanson
Path Finder

I had the same error, but mine was just file permissions. Changed the app's owner:group to splunk and the was able to save successfully.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

This sort of thing is usually about REST connections between the browser and Splunk... diagnosing what the problem is requires some knowledge of platform and environment. You should probably open a support case.

0 Karma

mduckett
Engager

Ok, thanks I'll do that. I did update the IPS add-on 2.1.4 but am still seeing the same.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...