This Add-On is basically a stripped version of App for McAfee Web Gateway (https://splunkbase.splunk.com/app/1654/) and provides ingestion settings (TIME_FORMAT etc.), index-time modifications (TRANSFORMS, SEDCMD), search-time extractions and CIM mapping for all four known sourcetypes for McAfee Web Gateway. It is indended for installation on Forwarders and Indexers in distributed Splunk environment. For a single Splunk server deployment (all-in-one box) and Search Heads use App for McAfee Web Gateway (https://splunkbase.splunk.com/app/1654/) instead.
This Add-On should work as-is in most cases and needs to be modified only if a timestamp format on MWG was changed. Follow installation guide for mcafee:webgateway:custom log format: https://proxy-test.com/Splunk_App_for_SkyHigh_Secure_Web_Gateway_README.html#log_format
NEW: Rsyslog/Syslog-NG interactive online configuration builder: https://proxy-test.com/Splunk_App_for_SkyHigh_Secure_Web_Gateway_README.html#interactive_configuration_builder - just enter destination, port and other parameters to generate ready to use configuration snippets.
https://youtu.be/vYy6ddpGkNw Splunk App for McAfee Web Gateway (MWG) - send logs to Splunk - step by step configuration
https://youtu.be/-nSkYdDQA00 Configure a McAfee Web Gateway (MWG) syslog to send TLS-secured data to Splunk
updated props/transforms for the compatibility with the McAfee/SkyHigh App up to 5.0.3. Added parsing of SSE/WGCS logs up to API version 12.
Fixed a TIME_PREFIX for wgcs_v5
added sc_admin role to default.meta, fixed typo in label
add support for all known available sourcetypes for McAfee Web Gateway: new mcafee:webgateway:custom, mcafee:webgateway:default and MWGaccess3 (also known as mcafee:wg:kv)
initial release
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.