Troubleshoot the Splunk Add-on for Websense DLP
General troubleshooting
For helpful troubleshooting tips that you can apply to all add-ons, see "Troubleshoot add-ons" in Splunk Add-ons. For additional resources, see "Support and resource links for add-ons" in Splunk Add-ons.
Data ingestion problems
Verify that you have configured the input correctly by confirming that:
- you have configured the correct IP address of the Splunk platform node responsible for data collection in your Websense DLP configuration.
- the port that you configured in your Websense DLP configuration matches the port you configured in your syslog input configuration.
- the port that you are using for this input does not conflict with any other inputs.
- your syslog input is configured to set the source type to
websense:dlp:system:cef
. - you are searching the correct index. By default, this add-on uses the
main
index.
Configure inputs for the Splunk Add-on for Websense DLP | Lookups for the Splunk Add-on for Websense DLP |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!