Hello,
I have installed Bluecaot proxySG app on my Splunk.
Related to the procedure below :
In Splunk, you will need to add a new TCP Data input. The app expects the source type to be bcoat_log. You may choose something different, but you will need to modify the app as well. Too add this input, log into Splunk and click on Manager. Under the Data section, click on "Data inputs". Then click on "Add new" for a TCP input. On this page, you can enter the port number, 20108 for example. You can optionally override the source name as well. Leave "Set sourcetype" as "From list", and choose bcoat_log from the dropdown list. Click on more settings, and set the index for this source to be bcoat_logs.
I configure my BC to send logs file to the splunk serve but the app dashboard display any result.
When I search whith index=bcoat_logs, I can see logs information. And a search with the sourcetype=bcoat_log, I have no results.
Do you an idea why it does not work ?
Thank you in advance.
I am also in the same issue.
I followed the tips in this page. But I keep getting a blank page in "BlueCoat Traffic Overview".
Hopefully someone will have another idea ?
Best Regards
Thank you for your answer.
After editing, it change nothing for the results.
When I search with the index or with bcoat_request
in the BC App Search Tab, I have see some logs with sourcetype="bcoat_proxysg" and source=bcoat.
But sourcetype="bcoat_proxysg" gives no results. I try this line (No results):
bcoat_request
filter_result="DENIED" src_ip != "-" | top src_ip limit=10 countfield="Requests" | rename src_ip as "Client IP"
No Dashboard display.
Any idea ?
Thanks in advance.
I add the index bcoat_logs in Indexes searched by default.
By typing just the name the index display some result.
But it changes nothing for the App dashboard, i.e it does not work.
Your list of default indexes searched (that is, if you don't explicitly say "index=...") is just "main" by default. Check out the roles (in the Manager under Access Controls) to see the "list of indexes searched by default".
(Or just type the name of the index in your searches....)
This app remaps incoming data from the "bcoat_logs" sourcetype to "bcoat_proxysg" (for matching events). When searching via the search bar, use the latter sourcetype. The app itself is keyed on the latter type, so your dashes should work just fine.