When I run | search index="_internal" sourcetype="sdee_connection" I get the following error:
Mon May 16 10:20:10 2011 - ERROR - Exception thrown while parsing SDEE payload: Traceback (most recent call last):
File "/opt/splunk/etc/apps/Splunk_CiscoIPS/bin/get_ips_feed.py", line 74, in run
alert_obj_list = idsmxml.parse_alerts( result_xml )
File "/opt/splunk/etc/apps/Splunk_CiscoIPS/bin/pysdee/idsmxml.py", line 240, in parse_alerts
alert_obj = build_global(alert)
File "/opt/splunk/etc/apps/Splunk_CiscoIPS/bin/pysdee/idsmxml.py", line 136, in build_global
alert.appname = node.getElementsByTagName('sd:originator')[0].getElementsByTagName('cid:appName')[0].firstChild.wholeText
IndexError: list index out of range
our splunkd.log
failed to parse timestamp for event. context="source::c:
Failed to parse timestamp for event. Context="soruce::c:
failed to parse timestamp for event.
context="source::c:
whats in your splunkd.log? It should have some messages in it which are relevant to the collection of these logs via the scripted input. I know there are people who have this configuration working out there.
Has anyone ever got this to work? I am trying to see the IPS alerts from my Cisco ISR router running the IOS IPS feature set. I run on the router sh ip sdee sub and can see that the router is sending the sdee alerts to the splunk server. I am running the latest splunk on a 64bit Ubuntu server. But other than that, absolutely nothing on the real time IPS Dashboard.
There was an error around this particular 'list index out of range' error that was resolved in 4.2.1, SPL-38100. If you haven't already, it may be a good idea to update the product to see if that resolves this problem.
We are getting the same error. Running on 4.2.5 windows forwarder (with forwarder license)