cancel
Showing results for 
Search instead for 
Did you mean: 
dconverse
Level 7

Trying to configure the Web Gateway access log in Splunk

Trying to configure the Web Gateway access log in Splunk while also retaining current logs data and formats from previous vendor. Previous license is specific the the source-type for the previous vendor. Anyone attempted this? Any assistance is appreciated.

0 Kudos
3 Replies
exbrit
Level 21

Re: Trying to configure the Web Gateway access log in Splunk

Moved to MWG for faster attention.

---

Peter

Moderator

0 Kudos
eelsasser
Level 15

Re: Trying to configure the Web Gateway access log in Splunk

Or in other words...

Has anyone tried to create a log handler rule to emulate the Cisco WSA format so the upstream logging reporting systems don't have to be changed? Just to save time until the upstream systems can be migrated.

0 Kudos
McAfee Employee

Re: Trying to configure the Web Gateway access log in Splunk

Web gateway can do anything!

If you need it to send logs to multiple servers, it can.

If you need to to send multiple log formats to multiple servers, it can.

We need details on the format in order to help you though.

Best Regards,

Jon

0 Kudos