I figured this out. I am very new to Splunk and didn't reailze the way this worked. When you install the webstats.spl file, the readme file gets extracted on the head server here:
\Program Files\Splunk\etc\apps\webstats
Also, the required add ons get extracted here:
\Program Files\Splunk\etc\apps\webstats\appserver\addons
and these need to be installed also. Once they are installed, you will be able to see their readme files in similar directories on the server and complete the required setup steps.
So, it's kind of working for me now. Still having some data issues, but I'll work through that.
... View more