Splunk Enterprise Security

BlueCoat ThreatPulse -- Does anyone have experience logging data from ThreatPulse?

jasonportico
Engager

Greetings -
I'm using BlueCoat ThreatPulse as a web filter ('cloud' based). The only method to pull their logs is via API. However, there isn't an app for ThreatPulse (and the ProxySG uses syslog). I've tinkered with the RESTapi app but haven't had any luck bringing in data. Is there anyone here that's used the RESTapi with ThreatPulse or have any other suggestions on getting this data into Splunk?

Thanks,
Jason

0 Karma

splunker288
Explorer

There is actually a TA and app that are available from Symantec now. I'm guessing they didn't exist at the time. Currently I'm having issues with it. It seems the API is not working. Is anyone having similar issues? It has worked fine for months but now when I run the input scripts I don't get anything back.

0 Karma

brian_rowe
Engager

There is a fairly straightforward way to accomplish this--download the Blue Coat Reporter app, install it on a server, and have it download the WSS/ThreatPulse logs automatically. Those logs come down in gzip format, but can be indexed easily by Splunk--the format is similar to the standard ProxySG log formats.

Here's an article from Symantec on setting up the connection between Reporter and ThreatPulse: https://support.symantec.com/en_US/article.TECH241105.html

jasonportico
Engager

Thanks Brian, I appreciate the reply.

While I couldn't find any solid answer at the time, I decided to go the manual route. I wrote a python script to download the log files on the hour and then place them in a directory that Splunk monitors.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...