All Apps and Add-ons

App for Web Proxies: How to troubleshoot why there is no data in the Web Proxy Traffic Overview?

mudricd
Explorer

Hi,

I would like to analyze Sophos Web Gateway logs. I installed your app according to the provided short manual, but there are no data in web proxy traffic overview. Could you please advise on this?

Cheers,
Dragan

Tags (1)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

You need to check your sourcetypes and make sure they match what the app is looking for. You should be able to drill into one of the searches in the dashboards, and see what its pulling from.

0 Karma

mudricd
Explorer

Hi guys,

I have enabled web acceleration couple of hours ago but status is still "Building". I am not sure how long does this take.

Where can I check sourcetype for app's searches? From the search from one of the panels I cannot figure:

| web_proxy_tstats_pre count from datamodel=Web where nodename=Web.Proxy by _time,Web.action,Web.http_method span=10m | rename Web.action AS action Web.http_method AS http_method | timechart minspan=10m useother=false count by action

Thanks guys for helping me out with this!

Cheers,
Dragan

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Check in the macros for that app. That's a macro. Additionally, I would check the README.. It should say what the expected data sources are...

0 Karma

dshpritz
SplunkTrust
SplunkTrust

This is using the Web data model, so the app itself doesn't really care about data sources. As long as the proxy data is correctly tagged ("web" and "proxy") and the fields extracted are CIM compliant, any proxy data should work.

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Hey Dragan,

Did you accelerate the Web data model? If so, it may take a while for it to start accelerating the data. You can check the progress by looking at the data models management page (see here).

Thanks,

Dave

0 Karma

mudricd
Explorer

Do you know how long web acceleration building takes? I enabled it yesterday and status is still building...

Thanks

0 Karma

dshpritz
SplunkTrust
SplunkTrust

It can take a while, especially if you are backfilling a large amount of data. It should give you a percentage to see how far along it is.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...