All Apps and Add-ons

CIM compliant event mapping for BlueCoat logs

skoops
New Member

Hi,
Has anyone managed to create a custom parser/sourcetype which maps all relevant BlueCoat access Log fields into the Common Information Model?
Will this become a feature in an upcoming version of the Splunk for BlueCoat App?
We'd like to "natively" include BlueCoat data into the ES App (and other CIM-aware apps and dashboards)
Best wishes,
Adam

0 Karma

Skorfulose
Explorer

Hi Adam,

have you tried "TA-bluecoat" (included in ES App). Works fine with the fields relevant for us. Also try the "App for Webproxies". Excellent piece!

Regards,
Thomas

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials

Welcome to the "Splunk Classroom Chronicles" series, created to help curious, career-minded learners get ...

Access Tokens Page - New & Improved

Splunk Observability Cloud recently launched an improved design for the access tokens page for better ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...