I am looking for for some troubleshooting pointers for the following issue:
I believe I have discovered a solution to this problem.
Under Settings -> Event Types -> Splunk Add-on for Cisco WSA
The tag was not set for the cisco:wsa:squid event-type
Once this was changed and the Web Data Model was rebuilt, events began to populate in Cisco ES
View solution in original post