icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

staging environment

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Splunk App for Web Analytics
SHA256 checksum (splunk-app-for-web-analytics_15.tgz) 65b22ae416ddd6139b85455e2d4ec0bea1eb94795d348ef61e773830e3dbef55 SHA256 checksum (splunk-app-for-web-analytics_142.tgz) 0f4e7ddf8250cbb70beab1a52381eab6cc4ddf97f471642162d835561d2ab81d
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Splunk App for Web Analytics

This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
Using the Splunk App for Web Analytics you can get analytics on your weblogs similar to what you would find using various online services (Google Analytics, Omniture, Webtrends) . Contrary to those tools you will get the analytics based on your web log data rather than injecting javascripts into the web pages that report back information to a cloud service.

You can get up and running within minutes and as you are basing the analytics on web log data you can quickly perform analytics on historical data as well as new real-time data being indexed by Splunk. Web services based around a javascript collector will only work for future events. This app can work in conjunction with these other services where you can do data mining and hypothesis testing in Splunk before you deploy a tag or web tracking configuration change to a live environment.

1. Import web log data

The Splunk App for Web Analytics currently supports data from Apache and IIS logs. Make sure you use the sourcetype access_common, access_combined or iis for this data. If you already have data in Splunk under a different sourcetype you can use sourcetype renaming or by modifying the eventtype web-traffic to include the names of your sourcetypes.

The app comes with two sets of sample data for Apache and IIS. You can enable these static sample inputs by going into Settings->Data inputs->Files & Directories

If your data is stored in an index that is not searched by default for your Splunk user, you need to add All non-internal indexes (or the specific index in question) to the Selected indexes in Access controls -> Roles -> [ROLE NAME]

2. Configure websites

The Splunk App for Web Analytics works in a multi website environment. Websites are configured from a combination of the host and the source field. Each event with that unique combination will be tagged with the corresponding website name in the field "site". You can use wildcards (*) in the Source and Host field to select multiple files matching a pattern. There is a website setup form page that allows you to add these in an easy way.

Here are some examples of valid website configurations with or without wildcards

No wildcards
Site Host Source
roadrunner.com server1 /var/log/httpd/access_log
roadrunner.com server2 /var/log/httpd/access_log

With wildcards
Site Host Source
roadrunner.com server /var/log/httpd/access_

The data in the setup form will be stored in the lookup file called WA_settings.csv. You can also manually edit this file. The websites setup page can be found under Setup->Websites.

3. Run lookups

Once the data has been imported run the two lookups "Generate user sessions" and "Generate pages". These will be used throughout the app. Once run the first time, they will automatically be updated via two scheduled searches that runs every 10 minutes that adds any new data coming into the app. Running these lookup searches might take a long time depending on how much data you have in Splunk but its important you let the searches finish before you move on to the next step. If you have too much data to run these for everything you can modify the time period to something less than "All time" which is the default time period. The lookup reports can be found under Setup->Lookups or by using the links above. It's important that thes searches return results. If not, the app will not work.

4. Enable data model acceleration

The Splunk App for Web Analytics uses data model acceleration extensively to power the dashboards. Once the lookups in the previous step has completed you should enable acceleration for the data model "Web". The data model can be found under Settings->Data models. Set the summary range appropriately depending on how long you want to keep the data, > 1 Month. The data model is updated every 10 minutes in order for the sessions to get picked up properly. The data model acceleration needs to finish before you will see any data in any dashboard except the "Real-Time" dashboard which uses raw log data as source. That means that you initially might not see data until the data model has finished building. This could initially take up to an hour depending on how much data it is trying to build.

5. Configure goals (Optional)

If you want to monitor certain browsing paths or pageviews you can configure goals. This is used if you for instance want to get conversion rates or funnel abandonment rates. You can find the Goals setup page under Goals->Goals Setup.

The goals are stored in a summary index called "goal_summary".

When enabling goals, the app will start monitor goal completions from the time you save the goal. To backfill goals there is a search called "Generate Goal summary - Backfill" which can be found under the Goals menu. Please note that running this search multiple times will mean the goal completions will be duplicated. To reset the goals you need to clean the "goal_summary" index.

Upgrade instructions

  1. Install app - Select "Upgrade App" checkbox.
  2. Disable Data Model acceleration for data model "Web".
  3. Run the "Generate user sessions" search.
  4. Once the session generation search is complete. Re-enable data model acceleration on the Data Models configuration page.
  5. Expand data model "Web" by clicking on the arrow on the left hand side. Click "Rebuild".

Troubleshooting

The lookup searches are not returning any data

In the context of the app, try and do the search for:

tag=web

If this is not returning any results I suspect you are not seeing the data because it is stored in a non-default index and the user in Splunk does not search in non-default indexes automatically. Another issue might be that you are not using any of the pre-configured sourcetypes. See Setup point 1 above.

If this is returning results, double check that each entry has the "site" field populated. It's crucial that this field exists in your data. See Setup point 2 above.

All or some dashboards are returning "No results found"

As the app relies heavily on data model accelerations you will not see anything in any dashboards (except the "Real-Time" ones) until this acceleration has completed. Initially this could take a while. There is a "Data Model Audit" dashboard that will tell you if the acceleration is complete or not.

Credits

The user agent parsing is based on an add-on developed by David Shpritz (TA-user-agents) who in turn uses a Python module from:
https://github.com/tobie/ua-parser

Release Notes

Version 1.5
Oct. 16, 2015
  • New Goal tracking framework. The documentation contains examples how to track customer checkouts for Magento and Woocommerce online stores.
  • Minor bug fixes

Please note that this upgrade will require a data model rebuild. See documentation for upgrade instructions.

Version 1.42
Oct. 6, 2015

Minor release
- Performance tweaks on the dashboards to use post-process searches were possible
- Refactored the scheduled searches to make it easier during initial install
- Changed all knowledge objects of the app to be visible to the app only instead of globally
- Updated the eventtypes
- Changed session cutoff time to 30 minutes instead of 15 minutes


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.