Splunk Enterprise Security

Splunk ES - Toubleshooting the Web Data Model

davidmonaghan
Explorer

Hi All

I am looking for for some troubleshooting pointers for the following issue:

  1. I have Splunk Enterprise Security installed and I am currently configuring it.
  2. Receiving logs from cisco:wsa:squid
  3. Splunk ES does not recognize the tags for the Web Data Model
  4. The following searches run successfully outside of the Splunk ES App | datamodel Web Web search or (cim_Web_indexes) (tag=web tag=proxy)
  5. The same searches fail inside the Splunk ES app
  6. All TAs have been added with global permissions
  7. The Data model has had it's constraints set (cim_Web_indexes) (tag=web)

Thanks

0 Karma
1 Solution

davidmonaghan
Explorer

I believe I have discovered a solution to this problem.

Under Settings -> Event Types -> Splunk Add-on for Cisco WSA

The tag was not set for the cisco:wsa:squid event-type

Once this was changed and the Web Data Model was rebuilt, events began to populate in Cisco ES

View solution in original post

0 Karma

davidmonaghan
Explorer

I believe I have discovered a solution to this problem.

Under Settings -> Event Types -> Splunk Add-on for Cisco WSA

The tag was not set for the cisco:wsa:squid event-type

Once this was changed and the Web Data Model was rebuilt, events began to populate in Cisco ES

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...