I cannot get any data to load into the application. I have followed all the pre-requisites:
I've tried opening up a dashboard panel in search, but it doesn't return any results even if I strip it down to:
| `web_proxy_tstats_pre` count from datamodel=Web
Any help or advice would be appreciated!
Hey scottmwa,
If that last search isn't populating with anything, it sounds like there isn't data in your data model. If you look at your websense events, are they tagged as "web" and "proxy"? That is, if you run a search like:
index=* tag=web tag=proxy
Do you get events?
Thanks,
Dave
Dave,
Thanks, for the reply. It does not appear that anything is getting tagged "web" or "proxy". How can I set up those tags?
Thanks,
Scott
When you said "The TA is installed", which TA did you mean? Typically TAs are used to extract fields from the events, and also provide eventtypes and tags for Common Information Model (CIM) compliance. Splunk Enterprise Security does come with a TA for websense proxies: http://docs.splunk.com/Documentation/ES/latest/CreateTA/Out-of-the-boxsourcetypes.