All Apps and Add-ons

App for Web Proxies: How to troubleshoot data input from Websense?

scottmwa
Explorer

I cannot get any data to load into the application. I have followed all the pre-requisites:

  • data is accelerated and at 100% on the web model
  • The TA is installed
  • wfa lookup macro is set to websense_wfa
  • websense version is 7.8.3
  • websense multiplexer and SEIM integration is turned on
  • data is flowing from websense -> index:"websense_input"

I've tried opening up a dashboard panel in search, but it doesn't return any results even if I strip it down to:

| `web_proxy_tstats_pre` count from datamodel=Web

Any help or advice would be appreciated!

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Hey scottmwa,

If that last search isn't populating with anything, it sounds like there isn't data in your data model. If you look at your websense events, are they tagged as "web" and "proxy"? That is, if you run a search like:

index=* tag=web tag=proxy

Do you get events?

Thanks,

Dave

0 Karma

scottmwa
Explorer

Dave,

Thanks, for the reply. It does not appear that anything is getting tagged "web" or "proxy". How can I set up those tags?

Thanks,

Scott

0 Karma

dshpritz
SplunkTrust
SplunkTrust

When you said "The TA is installed", which TA did you mean? Typically TAs are used to extract fields from the events, and also provide eventtypes and tags for Common Information Model (CIM) compliance. Splunk Enterprise Security does come with a TA for websense proxies: http://docs.splunk.com/Documentation/ES/latest/CreateTA/Out-of-the-boxsourcetypes.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...