Sourcetypes for the Splunk Add-on for Symantec Blue Coat ProxySG
The Splunk Add-on for Symantec Blue Coat ProxySG has two predefined source types. Use the one that matches the way you are ingesting your Blue Coat ProxySG data.
Sourcetype | Event type | Collection method | Limitations | CIM compliance |
---|---|---|---|---|
bluecoat:proxysg:access:kv
|
web, proxy | TCP or SC4S | No limitations. | Web |
bluecoat:proxysg:access:syslog
|
web, proxy | TCP or UDP | Logs should be unmodified from the default bcereportermain_v1 format. | Web |
bluecoat:proxysg:access:file
|
web, proxy | File monitoring | No limitations. Custom fields and field ordering supported. | Web |
Lookups for the Splunk Add-on for Symantec Blue Coat ProxySG | Release notes for the Splunk Add-on for Symantec Blue Coat ProxySG |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!