<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk web proxy query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-web-proxy-query/m-p/669762#M229655</link>
    <description>&lt;P&gt;Let's say my proxy is zscaler.&lt;/P&gt;&lt;P&gt;Now was able to fetch logs for rule "Uncategorised/Unknown URL" with vendor_signature as "Request method cautioned". This capture associated user who received a warning when he tried accessing suspicious/malicious page. He still continued to take the risk and access the URL. So, the idea is to build a usecase that would captured these warning pages followed by successful connection towards the page.&lt;/P&gt;</description>
    <pubDate>Sun, 26 Nov 2023 19:17:30 GMT</pubDate>
    <dc:creator>Raj7</dc:creator>
    <dc:date>2023-11-26T19:17:30Z</dc:date>
    <item>
      <title>Splunk web proxy query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-web-proxy-query/m-p/669756#M229651</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;Can someone please help me in building a query for user accessing webpage despite warning sign from proxy? &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/149"&gt;@splunk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2023 18:44:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-web-proxy-query/m-p/669756#M229651</guid>
      <dc:creator>Raj7</dc:creator>
      <dc:date>2023-11-26T18:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk web proxy query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-web-proxy-query/m-p/669760#M229654</link>
      <description>&lt;P&gt;And what data you have that shows this scenario?&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2023 19:10:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-web-proxy-query/m-p/669760#M229654</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-26T19:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk web proxy query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-web-proxy-query/m-p/669762#M229655</link>
      <description>&lt;P&gt;Let's say my proxy is zscaler.&lt;/P&gt;&lt;P&gt;Now was able to fetch logs for rule "Uncategorised/Unknown URL" with vendor_signature as "Request method cautioned". This capture associated user who received a warning when he tried accessing suspicious/malicious page. He still continued to take the risk and access the URL. So, the idea is to build a usecase that would captured these warning pages followed by successful connection towards the page.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2023 19:17:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-web-proxy-query/m-p/669762#M229655</guid>
      <dc:creator>Raj7</dc:creator>
      <dc:date>2023-11-26T19:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk web proxy query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-web-proxy-query/m-p/669837#M229672</link>
      <description>&lt;P&gt;I don't know zscaler logs but this task can be tricky. While the general approach seems to be relatively straightforward (just search, group by URL and user with the stats command and check if you have both the vendor_signature as well as successful request for the same URL/user pair), it might not be that easy to execute since proxies are usually quite talkative so if you did this over a longer timeframe the amount of returned data could overwhelm your SH.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 13:23:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-web-proxy-query/m-p/669837#M229672</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-27T13:23:52Z</dc:date>
    </item>
  </channel>
</rss>

