All Apps and Add-ons

Splunk Add-on for Blue Coat ProxySG: What is the regex for the host field extraction (proxy IP address) used by the bluecoat:proxysg:access:syslog source type?

noybin
Communicator

Hello,

Which is the regex for the host field extraction (not cs_host, but the proxy IP address) used by the bluecoat:proxysg:access:syslog source type?

I found the one used for syslog source type in etc/system/default/transforms.props, but I need the specific one for bluecoat:proxysg:access:syslog source type.

Thank you very much.

0 Karma

somesoni2
Revered Legend

I believe the configuration should be available $SPLUNK_HOME/etc/apps/Splunk_TA_bluecoat-proxysg directory. Check both default and local directories inside this one.

Reference: http://docs.splunk.com/Documentation/AddOns/latest/BlueCoatProxySG/Configureinputs

0 Karma
Get Updates on the Splunk Community!

New Cloud Intrusion Detection System Add-on for Splunk

In July 2022 Splunk released the Cloud IDS add-on which expanded Splunk capabilities in security and data ...

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...