This application was designed to give users usable data surrounding the requests being sent to their Barracuda Web Filter. The application was designed using data from a Barracuda Web Filter 310, even though the access logs should be universal across the Barracuda Web Filter family of appliances I cannot guarentee it will work with other versions.
Pre-deployment Assumptions:
1. You have enabled syslog logging on your Web Filter appliance.
2. The logs are being absorbed by Splunk and given a sourcetype name "barracuda"
3. You are using LDAP authentication. If you are not you may need to tweak the stanza named barracuda_without_ldap in transforms.conf
Reports in this Application:
Blocked/Allowed Traffic Reports:
You can also use the "Log Search" tab to manually search the logs using the defined categories.
TODO:
1. Configure a setup screen to change sourcetype name and/or specify an index
2. Add summary indexes for some of the reports
Small fixes for lookups.
Updates in version 1.7:
- New "Threat Intelligence" tab that will be used to collect external threat intelligence feeds and provide insight on any correlations that are found in your event data. Currently has support for phishtank.com through a scripted input that runs every 24 hours. More to be added soon.
- Updates to the regex's in transforms.conf
- Sourcetype renaming was added to match barracuda web filter syslog events and rename the sourcetype to "barracuda"
Some more clean up of the app. No major changes/fixes.
This release addresses two issues:
1. Saved search "Blocked Users by Requests" could not be found
2. Same values were appearing for "Top 10 Blocked Users" and "Top 10 Users by Allowed Requests"
Credit goes to Kirk G. from TekSecure Labs for finding the issues.
Very minor fix that was missed in last release
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.