All Apps and Add-ons

BlueCoat logs are not Processing

Kaushikkatta03
Explorer

Hello ,

In our splunk environment ,blueCoat logs are getting into Forwarder, but they aren't getting into the indexer from the forwarder . can anyone help us in troubleshooting or to find where the Problem is .Thanks in advance .

Tags (1)
0 Karma

adamblock2
Path Finder

Can you post additional information to help clarify your issue?

  • Are the logs being sent to syslog and then being forwarded to Splunk?
  • Are you using a heavy or universal forwarder?
  • Is the forwarder configured to forward other event logs or only BlueCoat? If the former, are the other event logs being properly forwarded to Splunk?
  • Have you tried stopping and restarting the forwarder service?

Thank you.

0 Karma

Kaushikkatta03
Explorer

some times when I try to find the "bluecoat_syslogs" through the search head , i'm getting the logs sometimes and sometimes it gives 'no results found' . May i know why this is happening ,how to overcome the issue.

0 Karma

Kaushikkatta03
Explorer

Hello Adam ,

We are using Heavy forwarder . the logs are being sent to syslog and then forwarded to heavy forwarder,from the forwarder the logs are unable to getting into Indexer.

It was yesterday morning around 5.45 am is the last updated and up to now we are unable to see any log being getting generated

Other event logs are being properly forwarded and indexed .

I have restarted the forwarder service and still unable to find the logs being updated .

-Thanks

0 Karma

adamblock2
Path Finder

Are the BlueCoat logs still being forwarded to the syslog server? Have you noticed errors in any of the log files (splunkd.log, etc.)?

Thank you.

0 Karma

Kaushikkatta03
Explorer

hello Adam ,

This is the stanza we tried to execute and check for the logs

"[monitor:///opt/syslogs/proxy/...]
whitelist = .log$
sourcetype = bluecoat_syslog
index = net_proxy
host_segment = 4"

We have verified the splunkd.log , we cannot see any error in that .the data is getting injected but it is intermediate .

Is there any other way to fix it Permanently,

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...