All Apps and Add-ons

App for Web Proxies: How to troubleshoot data input from Websense?

scottmwa
Explorer

I cannot get any data to load into the application. I have followed all the pre-requisites:

  • data is accelerated and at 100% on the web model
  • The TA is installed
  • wfa lookup macro is set to websense_wfa
  • websense version is 7.8.3
  • websense multiplexer and SEIM integration is turned on
  • data is flowing from websense -> index:"websense_input"

I've tried opening up a dashboard panel in search, but it doesn't return any results even if I strip it down to:

| `web_proxy_tstats_pre` count from datamodel=Web

Any help or advice would be appreciated!

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Hey scottmwa,

If that last search isn't populating with anything, it sounds like there isn't data in your data model. If you look at your websense events, are they tagged as "web" and "proxy"? That is, if you run a search like:

index=* tag=web tag=proxy

Do you get events?

Thanks,

Dave

0 Karma

scottmwa
Explorer

Dave,

Thanks, for the reply. It does not appear that anything is getting tagged "web" or "proxy". How can I set up those tags?

Thanks,

Scott

0 Karma

dshpritz
SplunkTrust
SplunkTrust

When you said "The TA is installed", which TA did you mean? Typically TAs are used to extract fields from the events, and also provide eventtypes and tags for Common Information Model (CIM) compliance. Splunk Enterprise Security does come with a TA for websense proxies: http://docs.splunk.com/Documentation/ES/latest/CreateTA/Out-of-the-boxsourcetypes.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...