splunkninja

The dojo of Splunk. Learn, share, teach, mentor.

Recently, I've seen a number of folks who have been trying to use the Splunk for Blue Coat Proxy SG app and the proxy together so the logs come in to Splunk and they are displayed properly in Splunk.



Check out this guide, I hope it helps!

Big props go out to SplunkNinja community member and Blue Coat Pre-Sales ninja Ty Morton

Tags: app, blue, coat, document, help, proxy, setup, splunk

Comment

You need to be a member of splunkninja to add comments!

Join splunkninja

Bob Munson Comment by Bob Munson on May 1, 2010 at 8:33am
Thanks for the info. My customer wants to setup an SSL connection so when I get it working, I send an update.
Michael Wilde Comment by Michael Wilde on April 29, 2010 at 5:29pm
Bob. This is actually not syslog. While it is TCP, it's a push in to Splunk. My friend at BlueCoat helped we set up this method as he said BC isn't that great at syslogging. If you know otherwise let me know and we'll update the guide.
Bob Munson Comment by Bob Munson on April 29, 2010 at 8:44am
Two questions.
1 As it is this just seems to be setting up syslog on a new port. What do we gain over using 514?
2 Would it be easy to secure this with SSL?

© 2010   Created by Michael Wilde.   Powered by .

Badges  |  Report an Issue  |  Terms of Service

Sign in to chat!