Splunk Enterprise Security

Splunk ES - Toubleshooting the Web Data Model

davidmonaghan
Explorer

Hi All

I am looking for for some troubleshooting pointers for the following issue:

  1. I have Splunk Enterprise Security installed and I am currently configuring it.
  2. Receiving logs from cisco:wsa:squid
  3. Splunk ES does not recognize the tags for the Web Data Model
  4. The following searches run successfully outside of the Splunk ES App | datamodel Web Web search or (cim_Web_indexes) (tag=web tag=proxy)
  5. The same searches fail inside the Splunk ES app
  6. All TAs have been added with global permissions
  7. The Data model has had it's constraints set (cim_Web_indexes) (tag=web)

Thanks

0 Karma
1 Solution

davidmonaghan
Explorer

I believe I have discovered a solution to this problem.

Under Settings -> Event Types -> Splunk Add-on for Cisco WSA

The tag was not set for the cisco:wsa:squid event-type

Once this was changed and the Web Data Model was rebuilt, events began to populate in Cisco ES

View solution in original post

0 Karma

davidmonaghan
Explorer

I believe I have discovered a solution to this problem.

Under Settings -> Event Types -> Splunk Add-on for Cisco WSA

The tag was not set for the cisco:wsa:squid event-type

Once this was changed and the Web Data Model was rebuilt, events began to populate in Cisco ES

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...