I have added three sensors to the inputs.conf file, but I am only able to see events from the first one. I can see Splunk is querying the other two and getting responses, but the data is not showing up. Is there something special I need to do for more than one sensor?
Thanks, this is awesome and fills a major gap in the Cisco IPS system. Splunk and this add-in are much better than MARS.
... View more