All Apps and Add-ons

App for Web Proxies: How to troubleshoot data input from Websense?

scottmwa
Explorer

I cannot get any data to load into the application. I have followed all the pre-requisites:

  • data is accelerated and at 100% on the web model
  • The TA is installed
  • wfa lookup macro is set to websense_wfa
  • websense version is 7.8.3
  • websense multiplexer and SEIM integration is turned on
  • data is flowing from websense -> index:"websense_input"

I've tried opening up a dashboard panel in search, but it doesn't return any results even if I strip it down to:

| `web_proxy_tstats_pre` count from datamodel=Web

Any help or advice would be appreciated!

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Hey scottmwa,

If that last search isn't populating with anything, it sounds like there isn't data in your data model. If you look at your websense events, are they tagged as "web" and "proxy"? That is, if you run a search like:

index=* tag=web tag=proxy

Do you get events?

Thanks,

Dave

0 Karma

scottmwa
Explorer

Dave,

Thanks, for the reply. It does not appear that anything is getting tagged "web" or "proxy". How can I set up those tags?

Thanks,

Scott

0 Karma

dshpritz
SplunkTrust
SplunkTrust

When you said "The TA is installed", which TA did you mean? Typically TAs are used to extract fields from the events, and also provide eventtypes and tags for Common Information Model (CIM) compliance. Splunk Enterprise Security does come with a TA for websense proxies: http://docs.splunk.com/Documentation/ES/latest/CreateTA/Out-of-the-boxsourcetypes.

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...