<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get support for the Splunk App for Web Analytics? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159545#M14727</link>
    <description>&lt;P&gt;Some more information for you:&lt;/P&gt;

&lt;P&gt;Under Setup -&amp;gt; Websites I have configured a website with Source=&lt;EM&gt;W3SVC1&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Under Setup -&amp;gt; Lookups -&amp;gt; Generate User Sessions it returns data but Generate Pages does not return data.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2015 16:35:08 GMT</pubDate>
    <dc:creator>dglass0215</dc:creator>
    <dc:date>2015-04-28T16:35:08Z</dc:date>
    <item>
      <title>How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159539#M14721</link>
      <description>&lt;P&gt;Other than this question/answer forum, Is there a way to get support  for the Splunk App for Web Analytics?  I have not been able to get it to show any data.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 13:32:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159539#M14721</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2015-04-28T13:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159540#M14722</link>
      <description>&lt;P&gt;I think this forum is it. The app page specifically says "Community Supported."&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 13:50:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159540#M14722</guid>
      <dc:creator>aweitzman</dc:creator>
      <dc:date>2015-04-28T13:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159541#M14723</link>
      <description>&lt;P&gt;Well that is a shame because it doesn't sound like there are too many users who have been able to get it to work.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 13:53:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159541#M14723</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2015-04-28T13:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159542#M14724</link>
      <description>&lt;P&gt;Hi dglass2015&lt;/P&gt;

&lt;P&gt;You can use this forum or by clicking my name under the "Built by..." on the right hand side column on the app page.&lt;/P&gt;

&lt;P&gt;It's difficult to say what the problem might be without any details. In your other post you mention Splunk TA for Web logs. That TA does not do any data inputs and does not need to be configured at all. It just needs to be installed.&lt;/P&gt;

&lt;P&gt;Do you get any results for this search query?&lt;/P&gt;

&lt;P&gt;tag=web&lt;/P&gt;

&lt;P&gt;If you do, verify that the data model has been accelerated. &lt;/P&gt;

&lt;P&gt;If not, do you get anything for this query?&lt;/P&gt;

&lt;P&gt;index=* (sourcetype=access* OR sourcetype=iis)&lt;/P&gt;

&lt;P&gt;If not, the sourcetype for the data you have in Splunk is not according to the documentation. You can use sourcetype renaming, reimporting the data under a new sourcetype, or by modifying the eventtype definition.&lt;/P&gt;

&lt;P&gt;If you let me know more details I can try and help.&lt;/P&gt;

&lt;P&gt;J&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 15:03:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159542#M14724</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2015-04-28T15:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159543#M14725</link>
      <description>&lt;P&gt;I cross posted this to the original post here:&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/231174/splunk-app-for-web-analytics-has-no-data.html"&gt;http://answers.splunk.com/answers/231174/splunk-app-for-web-analytics-has-no-data.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 15:12:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159543#M14725</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2015-04-28T15:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159544#M14726</link>
      <description>&lt;P&gt;Hi J!&lt;/P&gt;

&lt;P&gt;Thanks for your reply.  I do get results when searching tag=web and the Data Model named Web is accelerated.  What other details can I provide to you?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 15:30:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159544#M14726</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2015-04-28T15:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159545#M14727</link>
      <description>&lt;P&gt;Some more information for you:&lt;/P&gt;

&lt;P&gt;Under Setup -&amp;gt; Websites I have configured a website with Source=&lt;EM&gt;W3SVC1&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Under Setup -&amp;gt; Lookups -&amp;gt; Generate User Sessions it returns data but Generate Pages does not return data.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 16:35:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159545#M14727</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2015-04-28T16:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159546#M14728</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;That leads me to believe the sites are not correctly setup. Make sure that both the source and the host field match exactly whatever you have in your data. I designed the Website setup page so you can click on the right hand side for all available host+source combinations and then enter the site name without needing to type anything. The source for an IIS site should be a complete folder structure string and not just W3SVC1. &lt;/P&gt;

&lt;P&gt;Once this is done, run the lookups again.&lt;/P&gt;

&lt;P&gt;Once the lookups are done, rebuild the data model by disabling acceleration and then re-enabling it. &lt;/P&gt;

&lt;P&gt;J&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2015 16:44:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159546#M14728</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2015-04-28T16:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159547#M14729</link>
      <description>&lt;P&gt;I meant to say that the source was W3SVC1 (surrounded with * at beginning and end.  The post is just not displaying the star).&lt;/P&gt;

&lt;P&gt;Either way, I Changed the source to C:\inetpub\logs\LogFiles\W3SVC1*  (Slashes are being stripped out from this path)&lt;/P&gt;

&lt;P&gt;This is not exactly what is listed in the Available host and source combinations as this lists a different source for each different day of IIS logs.  Source Examples: &lt;/P&gt;

&lt;P&gt;C:\inetpub\logs\LogFiles\W3SVC1\u_ex140630.log&lt;BR /&gt;
C:\inetpub\logs\LogFiles\W3SVC1\u_ex140701.log&lt;BR /&gt;
(Slashes are being stripped out from these paths)&lt;/P&gt;

&lt;P&gt;etc.&lt;/P&gt;

&lt;P&gt;Then I ran lookups again (Generate User Sessions still looks like it returns no results).  Then I rebuilt the data moidel.  Still no dice.&lt;/P&gt;

&lt;P&gt;Again, Thanks for your continued assistance!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:42:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159547#M14729</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2020-09-28T19:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159548#M14730</link>
      <description>&lt;P&gt;Any other assistance you can provide?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2015 15:01:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159548#M14730</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2015-04-29T15:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159549#M14731</link>
      <description>&lt;P&gt;Hi again&lt;/P&gt;

&lt;P&gt;I found a bug in a config file.&lt;/P&gt;

&lt;P&gt;Edit the file transforms.conf in this folder&lt;BR /&gt;
/etc/apps/SplunkAppForWebAnalytics/default&lt;/P&gt;

&lt;P&gt;Edit the stanza so it matches this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WA_settings]
filename = WA_settings.csv
match_type = WILDCARD(source)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will enable wildcard matching on the source field so you can have * in the source field in WA_settings.csv . I will shortly release an updated version of the app that has this enabled by default. &lt;/P&gt;

&lt;P&gt;In WA_settings.csv:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\inetpub\logs\LogFiles\W3SVC1*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 29 Apr 2015 15:14:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159549#M14731</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2015-04-29T15:14:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159550#M14732</link>
      <description>&lt;P&gt;Excellent!  Thank you very much!  I now am able to see data in the real-Time but the rest still shows no data.  I have disabled and re-enabled acceleration on the data model and have waited more than 20 minutes.  Is there anything else I need to do in order to see data on the other tabs?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2015 15:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159550#M14732</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2015-04-29T15:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159551#M14733</link>
      <description>&lt;P&gt;Make sure you re-run both lookups - they should both return results - and then disable and re-enable the data model acceleration for the data model Web. &lt;/P&gt;

&lt;P&gt;Let me know how you get along.&lt;/P&gt;

&lt;P&gt;J&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2015 16:00:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159551#M14733</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2015-04-29T16:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159552#M14734</link>
      <description>&lt;P&gt;That is what I did and then I started getting data on the real-time tab, but no data elsewhere.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2015 16:05:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159552#M14734</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2015-04-29T16:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159553#M14735</link>
      <description>&lt;P&gt;Has the data model finished building the index? You can see this by expanding the data model using the little arrow next to it. It should give you a percentage on how long it it has come.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2015 16:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159553#M14735</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2015-04-29T16:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159554#M14736</link>
      <description>&lt;P&gt;I do not see where this percentage that you speak of is located, However, It does show some data now.  However it seems like it is only showing data from today even if I choose something like Year to date.  Also under top operating systems it just shows "compatible" whereas I would have expected something like Windows 7.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2015 17:46:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159554#M14736</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2015-04-29T17:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159555#M14737</link>
      <description>&lt;P&gt;Can you double check you selected acceleration for more than 1 day? Set it to 1 month or more to get statistics further back. You can do this disabling and then re-enabling the acceleration.&lt;/P&gt;

&lt;P&gt;For the operating system, there might be something off with that field extraction. You should be able to modify that yourself. Perhaps the OS is not contained in the source data?&lt;/P&gt;

&lt;P&gt;J&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2015 08:09:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159555#M14737</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2015-05-01T08:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159556#M14738</link>
      <description>&lt;P&gt;Very helpful discussion. What is the location of WA_settings.csv ? It isn't in /etc/apps/SplunkAppForWebAnalytics/ ?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 14:39:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159556#M14738</guid>
      <dc:creator>bbiandov</dc:creator>
      <dc:date>2015-07-17T14:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159557#M14739</link>
      <description>&lt;P&gt;Answered my own question: /opt/splunk/etc/apps/SplunkAppForWebAnalytics/lookups/&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 14:42:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159557#M14739</guid>
      <dc:creator>bbiandov</dc:creator>
      <dc:date>2015-07-17T14:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to get support for the Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159558#M14740</link>
      <description>&lt;P&gt;I have been looking at this app and trying to get some gauge of why my information stopped on a specific date on select reports. When I run the real time report I can see data streaming in as prescribed, however, when I go to the traffic center all of the traffic stops on April 3rd. I have gone through and applied all the test that you mentioned earlier in the post and everything is work as it should. Please let me know if you need any specific information in helping me troubleshoot this.&lt;/P&gt;

&lt;P&gt;Thank you,&lt;BR /&gt;
Ernie&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2016 15:46:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-support-for-the-Splunk-App-for-Web-Analytics/m-p/159558#M14740</guid>
      <dc:creator>ECovell</dc:creator>
      <dc:date>2016-04-18T15:46:43Z</dc:date>
    </item>
  </channel>
</rss>

