<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Has anyone gotten Splunk for Bluecoat working? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89550#M5934</link>
    <description>&lt;P&gt;Hi.&lt;/P&gt;

&lt;P&gt;I'm having a lot of problems with the Splunk for Bluecoat app.&lt;BR /&gt;
After following the tips from &lt;A href="http://splunk-base.splunk.com/answers/23395/could-someone-provide-some-tips-and-tricks-to-configure-splunk-for-bluecoat-application"&gt;this&lt;/A&gt; post i have gotten a little bit further, but still have a lot of problems.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;The searches in the app only works on the indexers. If I try to run the app on a search node, all searches fail with an error message:  "Reached end-of-stream while waiting for more data from peer index1. Search results might be incomplete!" (actually one of those from each indexer)&lt;/LI&gt;
&lt;LI&gt;Running the app on an indexer gives some data, but is slow to the point of being useless. A search for data for the last 15 minutes takes about 5 minutes to complete. Doing other searches (in the search app for instance) does not appear to very slow (although they are probably not so complex)&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;So my question is quite simply if anyone has gotten this app to work in a distributed environment, and if so how?&lt;/P&gt;

&lt;P&gt;Any tips would be appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Oct 2011 13:22:50 GMT</pubDate>
    <dc:creator>hcpr</dc:creator>
    <dc:date>2011-10-11T13:22:50Z</dc:date>
    <item>
      <title>Has anyone gotten Splunk for Bluecoat working?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89550#M5934</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;

&lt;P&gt;I'm having a lot of problems with the Splunk for Bluecoat app.&lt;BR /&gt;
After following the tips from &lt;A href="http://splunk-base.splunk.com/answers/23395/could-someone-provide-some-tips-and-tricks-to-configure-splunk-for-bluecoat-application"&gt;this&lt;/A&gt; post i have gotten a little bit further, but still have a lot of problems.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;The searches in the app only works on the indexers. If I try to run the app on a search node, all searches fail with an error message:  "Reached end-of-stream while waiting for more data from peer index1. Search results might be incomplete!" (actually one of those from each indexer)&lt;/LI&gt;
&lt;LI&gt;Running the app on an indexer gives some data, but is slow to the point of being useless. A search for data for the last 15 minutes takes about 5 minutes to complete. Doing other searches (in the search app for instance) does not appear to very slow (although they are probably not so complex)&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;So my question is quite simply if anyone has gotten this app to work in a distributed environment, and if so how?&lt;/P&gt;

&lt;P&gt;Any tips would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2011 13:22:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89550#M5934</guid>
      <dc:creator>hcpr</dc:creator>
      <dc:date>2011-10-11T13:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten Splunk for Bluecoat working?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89551#M5935</link>
      <description>&lt;P&gt;Not an answer, but I'm having the same exact problem. Not sure what the issue is..&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2011 14:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89551#M5935</guid>
      <dc:creator>trademarq</dc:creator>
      <dc:date>2011-10-26T14:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten Splunk for Bluecoat working?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89552#M5936</link>
      <description>&lt;P&gt;I've never got it to work on on our search heads either, but it does work mostly fine on the indexers themselves. I'm tempted to give up on it actually.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2011 15:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89552#M5936</guid>
      <dc:creator>tafiedler</dc:creator>
      <dc:date>2011-11-30T15:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten Splunk for Bluecoat working?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89553#M5937</link>
      <description>&lt;P&gt;I had problems too and gave up.&lt;BR /&gt;
As the description stated "Splunk and Blue Coat are teaming up..." I had hoped for much more.&lt;BR /&gt;
With the last update being 12 months ago I'm not sure this is going to go anywhere.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2012 12:16:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89553#M5937</guid>
      <dc:creator>jalford</dc:creator>
      <dc:date>2012-01-06T12:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten Splunk for Bluecoat working?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89554#M5938</link>
      <description>&lt;P&gt;First - I want to say I gave up on this and rolled the functionality for my bluecoat tracking into Enterprise Security. But, before I gave up, I found out that the bluecoat app is not designed to work in a distributed environment (at all). I had it working pretty well when I uninstalled it from everything and set it up to run solely on one indexer. A side effect of that is you have to send all your bluecoat traffic to one indexer. Hope this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2012 14:48:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89554#M5938</guid>
      <dc:creator>trademarq</dc:creator>
      <dc:date>2012-01-06T14:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten Splunk for Bluecoat working?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89555#M5939</link>
      <description>&lt;P&gt;hi i am also recieving this error in our distributed search environment ... has only from splunk been able to address this bug? i am using just the standard search app across a distro environment but encountering this error rather frequently.&lt;/P&gt;

&lt;P&gt;Even rerunning the search(s) doesnt seem to help.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2012 21:21:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89555#M5939</guid>
      <dc:creator>sairic81</dc:creator>
      <dc:date>2012-02-01T21:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten Splunk for Bluecoat working?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89556#M5940</link>
      <description>&lt;P&gt;This seems tied to the eventtype=bcoat_request in the BlueCoat - Datacube and BlueCoat - Datacube - Summary Index saved searches. &lt;/P&gt;

&lt;P&gt;By editing the saved search and replacing eventtype=bcoat_request in both searches with the expansion from macros.conf, i.e.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=bcoat_cacheflow OR (sourcetype=bcoat_proxysg  filter_result!="DENIED")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;the application works. Editing default/savedsearches.conf directly didn't seem to force this, even with a restart. Adding a local/savedsearches.conf with the correct stanzas (which I achieved through editing the saved search in Manager) does have the desired effect. &lt;/P&gt;

&lt;P&gt;local/savedsearches.conf now contains&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[BlueCoat - DataCube]
action.email.inline = 1
alert.digest_mode = True
alert.suppress = 0
alert.track = 0
search = sourcetype=bcoat_cacheflow OR (sourcetype=bcoat_proxysg  filter_result!="DENIED") |  bin _time span=5m | makemv delim=";" allowempty=t category |  fillnull src_ip cs_bytes category  dest_host rs_bytes sc_bytes sc_status sr_bytes  | eval client_bytes=sc_bytes+cs_bytes | eval server_bytes=rs_bytes+sr_bytes | eval savings_bytes=client_bytes-server_bytes | eval savings_bytes=if(server_bytes==0,0,savings_bytes) |  eval savings_perc = (1/client_bytes)  * savings_bytes * 100  | stats count by host src_ip sourcetype category dest_host server_bytes client_bytes savings_bytes savings_perc _time

[BlueCoat - DataCube - Summary Index]
action.email.inline = 1
alert.digest_mode = True
alert.suppress = 0
alert.track = 0
search = sourcetype=bcoat_cacheflow OR (sourcetype=bcoat_proxysg  filter_result!="DENIED") |  bin _time span=5m | makemv delim=";" allowempty=t category |  fillnull src_ip cs_bytes category  dest_host rs_bytes sc_bytes sc_status sr_bytes  | eval client_bytes=sc_bytes+cs_bytes | eval server_bytes=rs_bytes+sr_bytes | eval savings_bytes=client_bytes-server_bytes | eval savings_bytes=if(server_bytes==0,0,savings_bytes) |  eval savings_perc = (1/client_bytes)  * savings_bytes * 100  | sistats count by host src_ip sourcetype category dest_host server_bytes client_bytes savings_bytes savings_perc _time
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have no idea why the use of the eventtype foxes the distributed search - this could be a bug in Splunk. &lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2012 00:55:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89556#M5940</guid>
      <dc:creator>willthames2</dc:creator>
      <dc:date>2012-03-13T00:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten Splunk for Bluecoat working?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89557#M5941</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/9953"&gt;@trademarq&lt;/a&gt;:&lt;/P&gt;

&lt;P&gt;What all did you have to do to get the app to work, even in a non-distributed environment. I added data to an input; attached it to sourcetype='bcoat_proxysg' and on index='bcoat_logs'.&lt;/P&gt;

&lt;P&gt;When I open up the Blue Coat app I see "0BlueCoats Reporting&lt;BR /&gt;
Top Category:N/A&lt;BR /&gt;
Top Client:N/A&lt;BR /&gt;
Blocked Sites:"&lt;/P&gt;

&lt;P&gt;The Map below shows a few data points.&lt;/P&gt;

&lt;P&gt;A search for &lt;CODE&gt;bcoat_request&lt;/CODE&gt; displays all my data if the right time-period is chosen.&lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:30:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89557#M5941</guid>
      <dc:creator>mukulsud</dc:creator>
      <dc:date>2020-09-28T13:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten Splunk for Bluecoat working?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89558#M5942</link>
      <description>&lt;P&gt;I'm sorry that was over a year ago, I have no idea. I think there were still some quirks and I've just moved on from that app altogether.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2013 16:12:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89558#M5942</guid>
      <dc:creator>cedarcrestone</dc:creator>
      <dc:date>2013-03-13T16:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten Splunk for Bluecoat working?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89559#M5943</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;we can use the BlueCoat App for Splunk, but there still some fields that cannot be compared correctly.&lt;BR /&gt;
But for the first basic reports it's enough.&lt;BR /&gt;
We using it in this combination:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;The ProxySG's are using the an custom Accesslog Server, with the logformat "bcreportermain_v1"&lt;/LI&gt;
&lt;LI&gt;Because the custom logserver cannot use the local time, the ProxySG is sending the log in UTC, Splunk itself is running in local time (GMT+1)&lt;/LI&gt;
&lt;LI&gt;We have configures an local props file on Splunk:
/opt/splunk/etc/apps/SplunkforBlueCoat/local/props.conf&lt;/LI&gt;
&lt;/UL&gt;

&lt;HR /&gt;

&lt;P&gt;[bcoat_proxysg] &lt;/P&gt;

&lt;P&gt;TZ = UTC&lt;/P&gt;

&lt;P&gt;REPORT-main = bcreportermain_v1&lt;/P&gt;

&lt;HR /&gt;

&lt;UL&gt;
&lt;LI&gt;The data input for the dedicated TCP port has the sourcetype value "bcoat_proxysg", and the Index is "bcoat_logs"&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Now, after restarting Splunk, the fields are mostly correct like date, time, c-ip, but there are still some fields that are not 100% recognized. For an example, "action" has now the values from the http_statuscode. We haven't found a solution for it, because we are very beginners in Splunk, but when I compare the logformat with the transforms.conf, the order of the fields seems good.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:37:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Has-anyone-gotten-Splunk-for-Bluecoat-working/m-p/89559#M5943</guid>
      <dc:creator>carstenrremien</dc:creator>
      <dc:date>2020-09-28T13:37:30Z</dc:date>
    </item>
  </channel>
</rss>

