Troubleshoot the Splunk Add-on for Cisco WSA
For helpful troubleshooting tips that you can apply to all add-ons, see "Troubleshoot add-ons" in Splunk Add-ons. For additional resources, see "Support and resource links for add-ons" in Splunk Add-ons.
Cannot launch add-on
This add-on does not have views and is not intended to be visible in Splunk Web. If you are trying to launch or load views for this add-on and you are experiencing results you do not expect, turn off visibility for the add-on.
For more details about add-on visibility and instructions for turning visibility off, see Troubleshoot add-ons in Splunk Add-ons.
Extracted fields contain incorrect values
The Splunk add-on for Cisco WSA expects Cisco WSA access logs in a specific format for all its field extractions to work. If your Cisco WSA environment does not generate the logs in the order below, customize the event log format either in the add-on configuration or in Cisco WSA. See customize field extractions.
If your event log fields contain spaces, use the squid format instead of W3C format.
Field extractions for W3C formatted logs
Lookups for the Splunk Add-on for Cisco WSA
This documentation applies to the following versions of Splunk® Supported Add-ons: released