All Apps and Add-ons

Unable to create multi-valued field in Splunk_TA_bluecoat

pfabrizi
Path Finder

We had a discussion with a SPLUNK ES engineer and we installed the Splunk_TA_bluecoat app and using the stanza's in that app.

We are trying to get cs_categories moved to a multivalue field call category and we found that the props.conf and tranforms.conf have this code but we are not having any luck.
our source type is bluecoat:proxysg:access:kv
source =tcp:bluecoat

I am also guessing that REPORT keyword is only used when searching?

props.conf:
[bluecoat:proxysg:access:kv]
pulldown_type = true
category = Network & Security
description = Data from Blue Coat ProxySG in W3C ELFF format thru syslog
KV_MODE = auto
SHOULD_LINEMERGE = false
MAX_DAYS_AGO = 10951
EVENT_BREAKER_ENABLE = true
TRUNCATE = 64000

TRANSFORMS-TrashHeaders = TrashHeaders
SEDCMD-empty=s/ [a-zA-z0-9-]+=-//g

REPORT-categories = bluecoatkv_categories

transforms.conf:
[bluecoatkv_categories]
SOURCE_KEY = cs_categories
REGEX = (?[^;]+)
MV_ADD = true

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...