All Apps and Add-ons

Why are the "status_code" and "rep" fields necessary to identify uncategorized URLs in the App for McAfee Web Gateway?

dluiz
New Member

Can someone explain why the "status_code" and "rep" fields below are necessary to identify uncategorized URLs in the App for McAfee Web Gateway?

index=mwg sourcetype=MWGaccess3 status_code!=407 status_code="5*" urlc="-" rep!="-" 
0 Karma

PavelP
Motivator

Hello dluiz,

by excluding 5xx status codes you filter out various connectoins problems (like inability to resolve the destination host).
'rep!="-"' means include results where the Trusted Source Database was queried. In other case the results will include hosts from the white list.

best regards
Pavel

0 Karma

ppablo
Retired

Hi @dluiz

In case you don't get an answer here, you can always contact the developer of the app directly. The contact information for the developer of an app is found on the bottom right panel of the app's page:
https://apps.splunk.com/app/1654/

For the this particular app, they also put their contact information at the bottom of the Overview tab which is splunk@compek.net

0 Karma

dluiz
New Member

Thanks for the suggestions ppablo!

0 Karma

ppablo
Retired

No problem, hope ya find an answer soon 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...