All Apps and Add-ons

App for Web Proxies: How to troubleshoot data input from Websense?

scottmwa
Explorer

I cannot get any data to load into the application. I have followed all the pre-requisites:

  • data is accelerated and at 100% on the web model
  • The TA is installed
  • wfa lookup macro is set to websense_wfa
  • websense version is 7.8.3
  • websense multiplexer and SEIM integration is turned on
  • data is flowing from websense -> index:"websense_input"

I've tried opening up a dashboard panel in search, but it doesn't return any results even if I strip it down to:

| `web_proxy_tstats_pre` count from datamodel=Web

Any help or advice would be appreciated!

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Hey scottmwa,

If that last search isn't populating with anything, it sounds like there isn't data in your data model. If you look at your websense events, are they tagged as "web" and "proxy"? That is, if you run a search like:

index=* tag=web tag=proxy

Do you get events?

Thanks,

Dave

0 Karma

scottmwa
Explorer

Dave,

Thanks, for the reply. It does not appear that anything is getting tagged "web" or "proxy". How can I set up those tags?

Thanks,

Scott

0 Karma

dshpritz
SplunkTrust
SplunkTrust

When you said "The TA is installed", which TA did you mean? Typically TAs are used to extract fields from the events, and also provide eventtypes and tags for Common Information Model (CIM) compliance. Splunk Enterprise Security does come with a TA for websense proxies: http://docs.splunk.com/Documentation/ES/latest/CreateTA/Out-of-the-boxsourcetypes.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...