<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo Alto Globalprotect / VPN Dashboards? in Security</title>
    <link>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496099#M11327</link>
    <description>&lt;P&gt;With everyone working remotely nowadays, does anyone want to share their content on what a good PAN Global Protect dashboard could look like? &lt;BR /&gt;I know there's the Palo Alto Networks app that relies on the PAN data model, for those of us that don't use that app:&lt;BR /&gt;What panels do you like to have on your dashboard? &lt;BR /&gt;What's your favorite visualization for VPN connections? &lt;BR /&gt;Does anyone have some good SPL around duration time and data transferred during a session?&lt;/P&gt;
&lt;P&gt;Just so it doesn't seem like I'm asking someone to build me a dashboard. &lt;BR /&gt;My panels contain "Total number of users connected today", "Number of users connect to each gateway", " Number of users per department connected to VPN"&lt;/P&gt;
&lt;P&gt;Also, when is Palo Alto going to parse out the whole VPN event (OS, host, etc) that they dump into the system logs?&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Sun, 07 Jun 2020 17:18:26 GMT</pubDate>
    <dc:creator>TheSplunkDude</dc:creator>
    <dc:date>2020-06-07T17:18:26Z</dc:date>
    <item>
      <title>Palo Alto Globalprotect / VPN Dashboards?</title>
      <link>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496099#M11327</link>
      <description>&lt;P&gt;With everyone working remotely nowadays, does anyone want to share their content on what a good PAN Global Protect dashboard could look like? &lt;BR /&gt;I know there's the Palo Alto Networks app that relies on the PAN data model, for those of us that don't use that app:&lt;BR /&gt;What panels do you like to have on your dashboard? &lt;BR /&gt;What's your favorite visualization for VPN connections? &lt;BR /&gt;Does anyone have some good SPL around duration time and data transferred during a session?&lt;/P&gt;
&lt;P&gt;Just so it doesn't seem like I'm asking someone to build me a dashboard. &lt;BR /&gt;My panels contain "Total number of users connected today", "Number of users connect to each gateway", " Number of users per department connected to VPN"&lt;/P&gt;
&lt;P&gt;Also, when is Palo Alto going to parse out the whole VPN event (OS, host, etc) that they dump into the system logs?&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 17:18:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496099#M11327</guid>
      <dc:creator>TheSplunkDude</dc:creator>
      <dc:date>2020-06-07T17:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Globalprotect / VPN Dashboards?</title>
      <link>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496100#M11328</link>
      <description>&lt;P&gt;Yes! this is exactly what I am struggling with.. I am trying to build something but so far no luck...&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 13:49:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496100#M11328</guid>
      <dc:creator>pastorlibre</dc:creator>
      <dc:date>2020-03-17T13:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Globalprotect / VPN Dashboards?</title>
      <link>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496101#M11329</link>
      <description>&lt;P&gt;My team has actually been working on this. Not sure if anyone has made progress. We could probably share what we have thrown together. One issue we ran into is we are running PanOS 7.1, 8.1 and 9.1. And 9.1 hosts some of our VPN Gateways. PanOS 9, introduced new Global Protect logging that the Splunk Palo app; doesn't extract. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 15:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496101#M11329</guid>
      <dc:creator>mikesaia</dc:creator>
      <dc:date>2020-04-23T15:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Globalprotect / VPN Dashboards?</title>
      <link>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496102#M11330</link>
      <description>&lt;P&gt;If you could share anything that would be awesome.. We built something but it's not really the most ideal as it is a rolling 12 hour number and not really current&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 17:12:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496102#M11330</guid>
      <dc:creator>pastorlibre</dc:creator>
      <dc:date>2020-04-23T17:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Globalprotect / VPN Dashboards?</title>
      <link>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496103#M11331</link>
      <description>&lt;P&gt;I'd be keen on seeing what you have as well, and contributing to its development.&lt;BR /&gt;
I have actually started looking into changing the GP VPN dash (VPN Ops) in this app to display what it already has, but without the underlying data model that it uses from the Palo App. &lt;BR /&gt;
Remote Work Insights. &lt;A href="https://splunkbase.splunk.com/app/4952/+"&gt;https://splunkbase.splunk.com/app/4952/&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 22:28:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496103#M11331</guid>
      <dc:creator>markhill1</dc:creator>
      <dc:date>2020-04-23T22:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Globalprotect / VPN Dashboards?</title>
      <link>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496104#M11332</link>
      <description>&lt;P&gt;If there are any snippets you can share, I'd be grateful.  The one thing I haven't sorted out yet is how to create a "duration" report so my boss can see how long people are connecting for.  I'm a one man Splunker in a small gov entity so I just haven't the time to really dig into building my own searches like this.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 17:35:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496104#M11332</guid>
      <dc:creator>dking8921</dc:creator>
      <dc:date>2020-04-30T17:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Globalprotect / VPN Dashboards?</title>
      <link>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496105#M11333</link>
      <description>&lt;P&gt;Not a dashboard but here is something that I am running. Basically if they are on vpn and have an entry I give them credit for an hour.  Then I  pass that along to AD to get some information like department based on Ad info. Nice way to see who really is on vpn or not&lt;/P&gt;

&lt;P&gt;index="paloalto" src_zone=globalprotect action=success | eval hour_min=strftime(_time, "%D %H:00") | table hour_min , user, dvc_name src_ip | eval user=mvindex(split(user,"\"),-1) | rename hour_min as Time dvc_name as "Palo Alto Device" src_ip as vpn_ip | dedup user, Time|ldapfilter domain=default search="(sAMAccountNAme=$user$)" attrs="displayName,StreetAddress,Department,name" | table Time, "Palo Alto Device", vpn_ip, displayName, department, streetAddress, user , name,&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:19:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496105#M11333</guid>
      <dc:creator>elhugohefner</dc:creator>
      <dc:date>2020-09-30T05:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Globalprotect / VPN Dashboards?</title>
      <link>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496106#M11334</link>
      <description>&lt;P&gt;I tried running this command (with my correct index) and I just get zero matches no matter the length of time I put in.  I have the LDAP add on and the Palo Alto App, is there anything else I need to do to use this?  Thanks for sharing.&lt;/P&gt;

&lt;P&gt;Is this using the new GlobalProtect categories on 9.1.x?  I didn't upgrade to that yet, maybe that's why.&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 20:49:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496106#M11334</guid>
      <dc:creator>dking8921</dc:creator>
      <dc:date>2020-05-07T20:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Globalprotect / VPN Dashboards?</title>
      <link>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496107#M11335</link>
      <description>&lt;P&gt;Check where the ldapfilter domain  has your correct configuration in the ldap config on your search head. &lt;BR /&gt;
|ldapfilter domain=(yourdefined connector)&lt;/P&gt;

&lt;P&gt;Here is the link to get you the info to put in after the = &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SA-LdapSearch/3.0.1/User/ConfiguretheSplunkSupportingAdd-onforActiveDirectory"&gt;https://docs.splunk.com/Documentation/SA-LdapSearch/3.0.1/User/ConfiguretheSplunkSupportingAdd-onforActiveDirectory&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 22:33:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496107#M11335</guid>
      <dc:creator>elhugohefner</dc:creator>
      <dc:date>2020-05-07T22:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Globalprotect / VPN Dashboards?</title>
      <link>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496108#M11336</link>
      <description>&lt;P&gt;&lt;CODE&gt;sAMAccountName&lt;/CODE&gt; is correct.&lt;BR /&gt;
typo?&lt;/P&gt;

&lt;P&gt;please check line by line.&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 23:26:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Palo-Alto-Globalprotect-VPN-Dashboards/m-p/496108#M11336</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-07T23:26:12Z</dc:date>
    </item>
  </channel>
</rss>

