Has anyone imported data into Splunk from Websense Proxy in version 7.5?
Unfortunately, you cannot send to SIEM via Syslog and need to grab the data from the SQL Database.
If anyone has done this, do you mind sharing the process.
Hi Dimitris,
You could try exporting logs to specific location from websense and pick it up using a forwarder.
Or
You could try to pull data from SQL database using DBconnect app. (Since it is a proxy it might not be a good idea to put additional load on database.)
Thanks,
If anyone else has the same question, this is the query that I used.
Note: Some additional field extractions may be necessary.
"SELECT TOP 100000
i.date_time as [date],
i.record_number as session_id,
i.source_server_ip_int as dvc,
i.source_ip_int as src,
i.destination_ip_int as dest,
i.full_url,
i.url,
i.port,
p.name as app,
pc.name as app_category,
i.bytes_sent as bytes_out,
i.bytes_received as bytes_in,
i.duration,
i.category as category_id,
CASE when c.parent_category=0 then c.name
ELSE c.child_name END as category,
u.user_login_info as [user],
i.hits,
d.description as action_description,
dp.name as ws_action
FROM (((((incoming i left join users u on i.user_id=u.user_id)
left join protocols p on i.protocol_id=p.id)
left join protocol_category pc on p.parent_id=pc.id)
left join category c on i.category=c.category)
left join disposition d on i.disposition_code=d.disposition_code)
left join disposition_parent dp on d.blocking=dp.disposition_parent_id"
Hi Dimitris,
You could try exporting logs to specific location from websense and pick it up using a forwarder.
Or
You could try to pull data from SQL database using DBconnect app. (Since it is a proxy it might not be a good idea to put additional load on database.)
Thanks,
I will proceed with DB connect, and pull in the data from there and monitor also to see the load that it will apply by pulling the data.