Splunk Search

In the top 10 values of the "http_referrer" field, why is the first value empty?

mistydennis
Communicator

I'm in the process of analyzing events in some of our download logs. When I click on "http_referrer" it brings up the top 10 values for this field, however the very first value is blank. This first value is significantly higher than the others, so I'm interested in where this traffic is coming from. What does a blank http_referrer field mean?

0 Karma
1 Solution

DalJeanis
Legend

According to this page over at stack overflow, http_referrer is an unreliable field. Blank means it wasn't filled in. in some cases, that means the browser was in a private window or otherwise had privacy enabled, in others it might indicate that the referring page just didn't care enough to code it.

http://stackoverflow.com/questions/6023941/how-reliable-is-http-referer

According to THIS page - https://gispunt.wordpress.com/2012/01/10/why-using-referer-header-as-a-security-mechanism-is-a-bad-i...

"Most modern browsers have a “enhanced
privacy mode” that will remove the
referrer header next to refusing all
sorts of other tracking mechanisms,
which the header was initially
designed for."

View solution in original post

DalJeanis
Legend

According to this page over at stack overflow, http_referrer is an unreliable field. Blank means it wasn't filled in. in some cases, that means the browser was in a private window or otherwise had privacy enabled, in others it might indicate that the referring page just didn't care enough to code it.

http://stackoverflow.com/questions/6023941/how-reliable-is-http-referer

According to THIS page - https://gispunt.wordpress.com/2012/01/10/why-using-referer-header-as-a-security-mechanism-is-a-bad-i...

"Most modern browsers have a “enhanced
privacy mode” that will remove the
referrer header next to refusing all
sorts of other tracking mechanisms,
which the header was initially
designed for."

mistydennis
Communicator

Very useful information - thanks so much!

0 Karma

DalJeanis
Legend

you're welcome!

0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...