<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic web gateway filter activity to urls in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491799#M86067</link>
    <description>&lt;P&gt;i have 117 sites listed from homeland security. i need to check if any of our machine have visited them. We have McAfee web gateway logs funneled into splunk. What's the best way to go about looking for that activity?&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jun 2020 01:08:27 GMT</pubDate>
    <dc:creator>daveevad</dc:creator>
    <dc:date>2020-06-19T01:08:27Z</dc:date>
    <item>
      <title>web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491799#M86067</link>
      <description>&lt;P&gt;i have 117 sites listed from homeland security. i need to check if any of our machine have visited them. We have McAfee web gateway logs funneled into splunk. What's the best way to go about looking for that activity?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 01:08:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491799#M86067</guid>
      <dc:creator>daveevad</dc:creator>
      <dc:date>2020-06-19T01:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491800#M86068</link>
      <description>&lt;P&gt;ok, maybe i was making this harder than it needs to be. I can do this for example...&lt;BR /&gt;
source=Webgateway walmart.com&lt;BR /&gt;
i get alot of hits, of course. Do i have to do this 117 times, one for each url/ftp site?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 14:24:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491800#M86068</guid>
      <dc:creator>daveevad</dc:creator>
      <dc:date>2020-03-13T14:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491801#M86069</link>
      <description>&lt;P&gt;can i use "OR" statements between urls to search for several at one time?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 14:32:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491801#M86069</guid>
      <dc:creator>daveevad</dc:creator>
      <dc:date>2020-03-13T14:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491802#M86070</link>
      <description>&lt;P&gt;Ah, answer is yes. How many can i string together?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 14:34:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491802#M86070</guid>
      <dc:creator>daveevad</dc:creator>
      <dc:date>2020-03-13T14:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491803#M86071</link>
      <description>&lt;P&gt;apparently at least 10 sites. Was able to do searching without errors. Talked myself through this. I good now. Open to better ways though!&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 15:05:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491803#M86071</guid>
      <dc:creator>daveevad</dc:creator>
      <dc:date>2020-03-13T15:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491804#M86072</link>
      <description>&lt;P&gt;Are these website values part of a field in the data?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 16:04:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491804#M86072</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-03-13T16:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491805#M86073</link>
      <description>&lt;P&gt;as in my example for a walmart.com search, it showed up as &lt;BR /&gt;
dhost="beacon.walmart.com"&lt;BR /&gt;
That what you mean?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 17:22:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491805#M86073</guid>
      <dc:creator>daveevad</dc:creator>
      <dc:date>2020-03-13T17:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491806#M86074</link>
      <description>&lt;P&gt;yes, are other website names are part of this field?&lt;/P&gt;

&lt;P&gt;Provide some sample for below query.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source=Webgateway | head 20 | table dhost
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 13 Mar 2020 17:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491806#M86074</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-03-13T17:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491807#M86075</link>
      <description>&lt;P&gt;i had 117 various urls and ftp sites. I was checking to see if any of our user went to any of those site.  One of my queries looked like this.&lt;BR /&gt;
source=Webgateway &lt;A href="http://www.upanddown.ocry.com"&gt;www.upanddown.ocry.com&lt;/A&gt; OR dothi.chinhsech.com OR good.weascapes.com OR khinhte.chinhsech.com OR hcm.vozforumsx.com OR image.biengioivn.com OR lat.conglyan.com OR login.chinhphuna.com OR login.haiduongpcg.com OR luan.conglyan.com&lt;BR /&gt;
Which worked, i threw in a youtube.com and a walmart.com in there to check. A table would be cleaner though...&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 17:31:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491807#M86075</guid>
      <dc:creator>daveevad</dc:creator>
      <dc:date>2020-03-13T17:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491808#M86076</link>
      <description>&lt;P&gt;You can create a csv file with all the 117 urls, &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Usefieldlookupstoaddinformationtoyourevents#Upload_the_lookup_table_file"&gt;upload it in search head&lt;/A&gt; and use that in your search. This will filter data with all the urls in csv file.&lt;/P&gt;

&lt;P&gt;urls.csv&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;dhost&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="http://www.upanddown.ocry.com"&gt;www.upanddown.ocry.com&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://www.upanddown.ocry.com"&gt;www.upanddown.ocry.com&lt;/A&gt;&lt;BR /&gt;
good.weascapes.com&lt;BR /&gt;
khinhte.chinhsech.com&lt;BR /&gt;
...&lt;/P&gt;

&lt;P&gt;Search query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source=Webgateway [ | inputlookup urls.csv]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 13 Mar 2020 17:36:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491808#M86076</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-03-13T17:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491809#M86077</link>
      <description>&lt;P&gt;cool! thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 18:21:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491809#M86077</guid>
      <dc:creator>daveevad</dc:creator>
      <dc:date>2020-03-13T18:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491810#M86078</link>
      <description>&lt;P&gt;I converted my comment to answer. Please accepts it if it works for you.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 18:27:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491810#M86078</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-03-13T18:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: web gateway filter activity to urls</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491811#M86079</link>
      <description>&lt;P&gt;such lists (example: &lt;A href="https://urlhaus.abuse.ch/browse/"&gt;https://urlhaus.abuse.ch/browse/&lt;/A&gt;) often contains full urls with http:// prefix. A url &lt;A href="http://www.example.com/"&gt;http://www.example.com/&lt;/A&gt; from the csv file will not match &lt;A href="https://www.example.com/foo?xx"&gt;https://www.example.com/foo?xx&lt;/A&gt; in your proxy log. It is better to extract the domain part (&lt;A href="http://www.example.com"&gt;www.example.com&lt;/A&gt; or even example.com) before searching.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 22:58:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/web-gateway-filter-activity-to-urls/m-p/491811#M86079</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-03-13T22:58:17Z</dc:date>
    </item>
  </channel>
</rss>

