All Apps and Add-ons

Cisco Security Suite - Web Security

lamelendrez
Loves-to-Learn Lots

I am not getting any result for the Traffic Severity Panel on dashboard.

Looking at the search I have this

eventtype=css-wsa-squid http_result!="TCP_DENIED/407" | eval severity=cisco-wsa-score(x_wbrs_score) | eval severity=if(X-ScanVerdict=1,"red",severity) | timechart count by severity | table _time,red,orange,yellow,blue,green

I noticed the http_result is not a field on the search (running version 3.1.2 Cisco Security Suite & 3.2.3 on Cisco WSA)

What I dont now is what the eval severity=cisco-wsa-score(x_wbrs_score) does for me.

what is cisco-wsa-score?

Thanks in advance

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@lamelendrez

Which Splunk app you are using for viz??

It seems cisco-wsa-score is a macro. You will find the logic in macros.conf in Splunk app.

https://docs.splunk.com/Documentation/Splunk/7.3.2/Admin/Macrosconf

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutconfigurationfiles

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...