Troubleshoot the Splunk Add-on for Forcepoint Web Security
For helpful troubleshooting tips that you can apply to all add-ons, see Troubleshoot add-ons in Splunk Add-ons. For additional resources, see Support and resource links for add-ons in Splunk Add-ons.
Data ingestion problems
Verify that you have configured the input correctly by confirming the following points:
- You have configured the correct IP address of the Splunk platform node responsible for data collection in your Forcepoint Web Security configuration.
- The port that you configured in your Forcepoint Web Security configuration matches the port you configured in your syslog input configuration.
- The port that you are using for this input does not conflict with any other inputs.
- Your syslog input is configured to set the source type to
websense:cg:kv
. - You are searching the correct index. By default, this add-on uses the
main
index.
Configure inputs for the Splunk Add-on for Forcepoint Web Security | Lookups for the Splunk Add-on for Forcepoint Web Security |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!