Refine your search:

Thanks For Downloading!

Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows:

Windows: Decompress the downloaded file using a tool like 7-Zip and place the resulting folder into %PROGRAMFILES%\Splunk\etc\apps. Then restart Splunk using the splunk restart command or the GUI.

Unix/Linux: Decompress the downloaded file using a tool like tar -xvf and place the resulting folder into $SPLUNK_HOME/etc/apps. Then restart Splunk using the splunk restart command or the GUI.

Description

An updated version of this app with support for PorxySG and CacheFlow can be found here:

http://splunkbase.splunk.com/apps/All/4.x/App/app:Splunk+for+BlueCoat

Documentation can be found here: http://www.splunk.com/goto/splunkforbluecoatsetup

Versions and Release Notes

Version 1.2 (current version - updated Mar 11, 2010)
show older versions »
Version 1.1 (updated Jan 07, 2010)
Version 1.0 (updated Dec 09, 2009)
Version Beta 4 (updated Oct 26, 2009)
Version Beta1.2 (updated Jul 21, 2009)
Version Beta2 (updated Jul 21, 2009)
Version Beta1.1 (updated Jul 21, 2009)
Version Beta1 (updated Jul 19, 2009)
Version 0.91 (updated Jul 14, 2009)
Version 0.9 (updated Jul 13, 2009)

posted 13 Jul '09, 22:27

Will%20Hayes's gravatar image

Will Hayes ♦
2.9k6817
accept rate: 16%

new version 11 Mar '10, 05:17


4 Reviews:
0 ratings

dont think it matters as the log format is still the same.

comments (0)

reviewed 14 Mar, 19:22

th0i3's gravatar image

th0i3
1
accept rate: 0%

noticed on the latest 4.3.1 upgrade in splunk the config checker found this:

Possible typo in stanza [class_id] in /app/splunk/etc/apps/SplunkforBlueCoat/default/transforms.conf, line 49: SOURC_KEY = ClassID Possible typo in stanza [class_id] in /app/splunk/etc/apps/SplunkforBlueCoat/default/transforms.conf, line 54: SOURC_KEY = ClassID Possible typo in stanza [class_id] in /app/splunk/etc/apps/SplunkforBlueCoat/default/transforms.conf, line 59: SOURC_KEY = ClassI

i think it should be SOURCE_KEY = ClassID

comments (0)

reviewed 07 Mar, 09:14

EricPartington's gravatar image

EricPartington
3047
accept rate: 50%

Will, We pull our logs via Syslog-ng and ran into problems with the space delimited fields. I've rewritten parts of your app and would like to share them with you. Please let me know how to get this information to you.

The destination filter in Syslog-ng that was used is:

destination df_splunk4bluecoat {

    file("/var/log/network/bluecoat/$HOST/syslog-ng.log"
    owner(root) group(adm) perm(0640) dir_perm(0750) dir_group(adm) create_dirs(yes)
    template("$MSG\n") );

}

Joe

comments (0)

reviewed 01 Nov '11, 06:48

jgedeon120's gravatar image

jgedeon120
1135
accept rate: 16%

Hi, does this version support Bluecoat Proxy SG SGOS 5.3.3.1 ?

comments (0)

reviewed 06 May '11, 21:52

abbasali's gravatar image

abbasali
1
accept rate: 0%

Your review

Did you find this app useful?

Preview toggle preview

Details

This app is not covered by any support agreements in place with Splunk. If you have questions about the installation or operation of this app, please contact the author.

Version 1.2
Last Updated: Mar 11, 2010
Download App
Author: Will Hayes
Version: 1.2
Splunk compatibility: 4.3, 4.2, 4.1, 4.x
Price: Free
License: Splunk Master Software License Agreement
Downloads: 4,613

Follow this app

Log In to enable email subscriptions

RSS:

Reviews

Reviews + Comments

Copyright © 2005-2012 Splunk, Inc. All rights reserved.