Splunk Search

Bluecoat proxy query

shandman
Path Finder

Hello.

I'm trying to create a query that will show total traffic to a url. Showing total traffic by top users per day. So,

index=bluecoat url=urlhere user=userhere bytes_in=?? bytes_out=??

all field names are valid.. just trying to get the values to show how I want. being able to create a dashboard with a box where I could enter a user name and display those values would also be great.

Thank you in advance.

0 Karma

rajindurbal
Path Finder

Good afternoon @shandman ,

The easiest way to do this is with tokens on your dashboard. I suggest using the text input from the input dropdown at the top of the dashboard editor.

This link may assist you with creating tokens:
https://docs.splunk.com/Documentation/Splunk/7.2.6/Viz/tokens

Rajin

0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...