Refine your search:

Thanks For Downloading!

Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows:

Windows: Decompress the downloaded file using a tool like 7-Zip and place the resulting folder into %PROGRAMFILES%\Splunk\etc\apps. Then restart Splunk using the splunk restart command or the GUI.

Unix/Linux: Decompress the downloaded file using a tool like tar -xvf and place the resulting folder into $SPLUNK_HOME/etc/apps. Then restart Splunk using the splunk restart command or the GUI.

Description

Barracuda Web Filter App for Splunk

This application was designed to give users usable data surrounding the requests being sent to their Barracuda Web Filter. The application was designed using data from a Barracuda Web Filter 310, even though the access logs should be universal across the Barracuda Web Filter family of appliances I cannot guarentee it will work with other versions.

Pre-deployment Assumptions:

1. You have enabled syslog logging on your Web Filter appliance.
2. The logs are being absorbed by Splunk and given a sourcetype name "barracuda"
3. You are using LDAP authentication. If you are not you may need to tweak the stanza named barracuda_without_ldap in transforms.conf

Reports in this Application:

  • Top Users by Spyware Type
  • Top Domains by Spyware Type
  • Top Spyware Types
  • Top Source IPs by Spyware Type
  • Weekly Bandwidth Usage
  • Top Ten Bandwidth Consumers by User ID
  • Bandwidth Consumed by Hour of Day
  • Bandwidth Consumed by Day of Week
  • Domains by Bandwidth Consumed
  • Users by Bandwidth Consumed
  • Content Type by Bandwidth Consumed
  • Source IP by Bandwidth Consumed
  • Dest IP by Bandwidth Consumed

Blocked/Allowed Traffic Reports:

  • Domains by # of Requests
  • Domains by Category
  • Top Domains Accessed by User
  • Most Accessed Content Type by Domain
  • Most Accessed Category by Domain
  • Users by # of Requests
  • Categories by # of Requests
  • Top Category per User
  • Top Content Types
  • Source IPs by # of Requests
  • Dest IPs by # of Requests
  • Requests by Hour of Day
  • Requests by Day of Week

You can also use the "Log Search" tab to manually search the logs using the defined categories.

TODO:

1. Configure a setup screen to change sourcetype name and/or specify an index
2. Add summary indexes for some of the reports

Versions and Release Notes

Version 1.4 (current version - updated Sep 28, 2011)
release notes:
Very minor fix that was missed in last release
show older versions »
Version 1.3 (updated Sep 28, 2011)
release notes:
- Updated the log search page to properly incorporate the Action field and display it in the results. - Fixed two blocked reports in the activity by domain dashboard that were improperly labelled. - Changed the bandwidth by day report to be over the last 7 days by default.
Version 1.2 (updated Sep 27, 2011)
release notes:
- Added Blocked traffic - Separated menus into "Allowed" and "Blocked" traffic - Added action type (blocked/allowed) to the log search dashboard - Reorganized the reports on each dashboard - Added a specific "Bandwidth Usage" dashboard - Results will update when a new date/time frame is select from the drop down menu
Version 1.1 (updated Sep 26, 2011)
release notes:
- Added category definitions so the user can reference what criteria makes up a given category. - Fixed font type so it's a little prettier - Changed the title on one of the charts - Remove the defined time bucket on the Bandwidth Usage search.
Version 1.0 (updated Sep 26, 2011)

posted 26 Sep '11, 01:44

joshd's gravatar image

joshd
6457
accept rate: 21%

new version 28 Sep '11, 14:57

Be the first one to review!

Did you find this app useful?

Preview toggle preview

Details

This app is not covered by any support agreements in place with Splunk. If you have questions about the installation or operation of this app, please contact the author.

Version 1.4
Last Updated: Sep 28, 2011
Download App
Author: joshd
Version: 1.4
Splunk compatibility: 4.3, 4.2, 4.1, 4.x
Price: Free
License: Creative Commons BY 3.0
Downloads: 145

Follow this app

Log In to enable email subscriptions

RSS:

Reviews

Reviews + Comments

Related Questions

 
Ask a Question

Related Apps

 
Copyright © 2005-2012 Splunk, Inc. All rights reserved.