<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do i get data into Splunk App for Web Analytics? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115858#M8627</link>
    <description>&lt;P&gt;In the context of the app, try and do the search for:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;tag=web
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If this is not returning any results I suspect you are not seeing the data because it is stored in a non-default index and the user in Splunk does not search in non-default indexes automatically. &lt;/P&gt;

&lt;P&gt;You need to add &lt;STRONG&gt;All non-internal indexes&lt;/STRONG&gt; to the &lt;STRONG&gt;Selected indexes&lt;/STRONG&gt; in &lt;STRONG&gt;Access controls » Roles » [ROLE NAME]&lt;/STRONG&gt;&lt;BR /&gt;
Alternatively you can add just the index where the apache log files are stored. &lt;/P&gt;

&lt;P&gt;There is a thread about this here:&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/237946/splunk-app-for-web-analytics-and-splunk-weblog-add.html"&gt;http://answers.splunk.com/answers/237946/splunk-app-for-web-analytics-and-splunk-weblog-add.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 11 Jul 2015 06:02:30 GMT</pubDate>
    <dc:creator>jbjerke_splunk</dc:creator>
    <dc:date>2015-07-11T06:02:30Z</dc:date>
    <item>
      <title>How do i get data into Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115856#M8625</link>
      <description>&lt;P&gt;Looking for some basic help with the Splunk Web Analytics Apps. &lt;/P&gt;

&lt;P&gt;Currently app is installed and pulling in the /var/log/httpd/* logs with sourcetype=apache_common. However not able to display any data.&lt;BR /&gt;
When I run the two lookups I don't get any result..wondering if my initial setup is correct.&lt;/P&gt;

&lt;P&gt;1) How do I get data in this app?  The documentation says "Make sure you use the sourcetype apache_common, apache_combined or iis for this data" My source is apache so what sourcetype do I use? apache_common or apache_combined? &lt;/P&gt;

&lt;P&gt;2) Are the /var/log/httpd/* logs all that are required for the app for soruce data?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:39:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115856#M8625</guid>
      <dc:creator>jcampomizzi</dc:creator>
      <dc:date>2020-09-29T06:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: How do i get data into Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115857#M8626</link>
      <description>&lt;P&gt;Have you looked at the documentation within the app?&lt;/P&gt;

&lt;P&gt;Right after it mentions&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Make sure you use the sourcetype apache_common, apache_combined or iis for this data.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;it says:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;If you already have data in Splunk under a different sourcetype you can use sourcetype renaming or by modifying the eventtype web-traffic to include the names of your sourcetypes&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;So you can rename it if you need to but it sounds like you already have the sourcetype named correctly.&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;In the documentation page in the app:&lt;/P&gt;

&lt;H3&gt;The second step says:&lt;/H3&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;The Splunk App for Web Analytics works in a multi website environment. Websites are configured from a combination of the host and the source field. Each event with that unique combination will be tagged with the corresponding website name in the field "site". There is a website setup form page that allows you to add these in an easy way. The data in the setup form will be stored in the lookup file called WA_settings.csv. You can also manually edit this file. The websites setup page can be found under Setup-&amp;gt;Websites or by using the link above.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;H4&gt;Did you configure it using the tool provided in the app?&lt;/H4&gt;

&lt;H3&gt;The third step says:&lt;/H3&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Once the data has been imported run the two lookups "Generate user sessions" and "Generate pages". These will be used throughout the app. Once run the first time, they will automatically be updated via two scheduled searches that runs every 10 minutes that adds any new data coming into the app. Running these lookup searches might take a long time depending on how much data you have in Splunk but its important you let the searches finish before you move on to the next step. The lookup reports can be found under Setup-Lookups or by using the links above. It's important that thes searches return results. If not, the app will not work.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;H4&gt;Did you run the lookups?&lt;/H4&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:38:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115857#M8626</guid>
      <dc:creator>aljohnson_splun</dc:creator>
      <dc:date>2020-09-29T06:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: How do i get data into Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115858#M8627</link>
      <description>&lt;P&gt;In the context of the app, try and do the search for:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;tag=web
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If this is not returning any results I suspect you are not seeing the data because it is stored in a non-default index and the user in Splunk does not search in non-default indexes automatically. &lt;/P&gt;

&lt;P&gt;You need to add &lt;STRONG&gt;All non-internal indexes&lt;/STRONG&gt; to the &lt;STRONG&gt;Selected indexes&lt;/STRONG&gt; in &lt;STRONG&gt;Access controls » Roles » [ROLE NAME]&lt;/STRONG&gt;&lt;BR /&gt;
Alternatively you can add just the index where the apache log files are stored. &lt;/P&gt;

&lt;P&gt;There is a thread about this here:&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/237946/splunk-app-for-web-analytics-and-splunk-weblog-add.html"&gt;http://answers.splunk.com/answers/237946/splunk-app-for-web-analytics-and-splunk-weblog-add.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2015 06:02:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115858#M8627</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2015-07-11T06:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: How do i get data into Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115859#M8628</link>
      <description>&lt;P&gt;Yes I read the documentation and the reason for my question #1.&lt;/P&gt;

&lt;P&gt;I am unclear which sourcetype to use for apache logs?  Can I use either or are both required for different inputs?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2015 14:41:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115859#M8628</guid>
      <dc:creator>jcampomizzi</dc:creator>
      <dc:date>2015-07-13T14:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: How do i get data into Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115860#M8629</link>
      <description>&lt;P&gt;Indexes are already part of default search...&lt;/P&gt;

&lt;P&gt;When I run the tag=web I don't get any results. Same for when I run the two built in lookups.&lt;/P&gt;

&lt;P&gt;Still not sure what is wrong....&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2015 14:42:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115860#M8629</guid>
      <dc:creator>jcampomizzi</dc:creator>
      <dc:date>2015-07-13T14:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: How do i get data into Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115861#M8630</link>
      <description>&lt;P&gt;One more clarification...I just realized the documentation says to use sourcetype=apache_combined however the sample data uses sourcetype=access_combined? Is there an issue with documentation or am I missing something?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:40:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115861#M8630</guid>
      <dc:creator>jcampomizzi</dc:creator>
      <dc:date>2020-09-29T06:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do i get data into Splunk App for Web Analytics?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115862#M8631</link>
      <description>&lt;P&gt;You are right the documentation is wrong - This has now been corrected.&lt;/P&gt;

&lt;P&gt;Just to clarify, the default sourcetypes for the app should be:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="iis"OR sourcetype="access_combined" OR sourcetype="access_common" OR sourcetype="access_combined_wcookie"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;j&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2015 16:25:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-i-get-data-into-Splunk-App-for-Web-Analytics/m-p/115862#M8631</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2015-07-13T16:25:24Z</dc:date>
    </item>
  </channel>
</rss>

