All Apps and Add-ons

App for Web Proxies: How to troubleshoot data input from Websense?

scottmwa
Explorer

I cannot get any data to load into the application. I have followed all the pre-requisites:

  • data is accelerated and at 100% on the web model
  • The TA is installed
  • wfa lookup macro is set to websense_wfa
  • websense version is 7.8.3
  • websense multiplexer and SEIM integration is turned on
  • data is flowing from websense -> index:"websense_input"

I've tried opening up a dashboard panel in search, but it doesn't return any results even if I strip it down to:

| `web_proxy_tstats_pre` count from datamodel=Web

Any help or advice would be appreciated!

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Hey scottmwa,

If that last search isn't populating with anything, it sounds like there isn't data in your data model. If you look at your websense events, are they tagged as "web" and "proxy"? That is, if you run a search like:

index=* tag=web tag=proxy

Do you get events?

Thanks,

Dave

0 Karma

scottmwa
Explorer

Dave,

Thanks, for the reply. It does not appear that anything is getting tagged "web" or "proxy". How can I set up those tags?

Thanks,

Scott

0 Karma

dshpritz
SplunkTrust
SplunkTrust

When you said "The TA is installed", which TA did you mean? Typically TAs are used to extract fields from the events, and also provide eventtypes and tags for Common Information Model (CIM) compliance. Splunk Enterprise Security does come with a TA for websense proxies: http://docs.splunk.com/Documentation/ES/latest/CreateTA/Out-of-the-boxsourcetypes.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...