All Apps and Add-ons

Why are the "status_code" and "rep" fields necessary to identify uncategorized URLs in the App for McAfee Web Gateway?

dluiz
New Member

Can someone explain why the "status_code" and "rep" fields below are necessary to identify uncategorized URLs in the App for McAfee Web Gateway?

index=mwg sourcetype=MWGaccess3 status_code!=407 status_code="5*" urlc="-" rep!="-" 
0 Karma

PavelP
Motivator

Hello dluiz,

by excluding 5xx status codes you filter out various connectoins problems (like inability to resolve the destination host).
'rep!="-"' means include results where the Trusted Source Database was queried. In other case the results will include hosts from the white list.

best regards
Pavel

0 Karma

ppablo
Retired

Hi @dluiz

In case you don't get an answer here, you can always contact the developer of the app directly. The contact information for the developer of an app is found on the bottom right panel of the app's page:
https://apps.splunk.com/app/1654/

For the this particular app, they also put their contact information at the bottom of the Overview tab which is splunk@compek.net

0 Karma

dluiz
New Member

Thanks for the suggestions ppablo!

0 Karma

ppablo
Retired

No problem, hope ya find an answer soon 🙂

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...