All Apps and Add-ons

What add-ons are needed for the Blue Coat apps, and where are these installed in a Search Head and Indexer Clustering environment?

nychawk
Communicator

Hello;

I am encountering issues with the Blue Coat app. It's not my first time deploying this app, and am considering instead just using this app, or apps; there seem to be many. https://splunkbase.splunk.com/apps/#/page/1/author/joel.ebrahimi/order/latest

My questions are:

Why are there so many different apps, versus just one?

What add-ons/TA's are needed, and where are these installed?

I already have my Bluecoats (SG's right now, soon to be ASG's) sending logs to syslog; I assume the documented sourcetype would work.

Thank you in advance.

0 Karma

joel_ebrahimi
Explorer

Blue Coat has created 1 Technical Add On for getting the data into Splunk and 1 App for dashboards around that data for the latest ProxySG. The TA is using the custom client to receive the data at this time. Ive included the documentation here that is available as well on BlueTouch Online in TAP Integrations.

Anyone is free to create apps based on any Blue Coat products, but Blue Coat only supports the ones created by them.

0 Karma

joel_ebrahimi
Explorer

Also just so you are aware, the 3 other Blue Coat apps you created tags for are for 3 other Blue Coat products. There is ProxySG as you are aware but there is also an App for Security Analytics and an App for Malware Analysis.

0 Karma

nychawk
Communicator

Splunk added a BlueCoat add-on late last year, which I assume is compatible with the BC app?

In terms of your own Add-on/TA, can I install that instead of the BC app and Splunk BC add-on?

I like the Bluecoat app, but from what I've read, others have been adding fixes and changes to the searches, but they never seem to make it into a newer release.

Thank you!

0 Karma

joel_ebrahimi
Explorer

The Blue Coat ProxySG TA is compatible with the Blue Coat ProxySG App. The other could probably work but it may require changing the sourcetype or other items but I do not really know.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...