<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloudflare app for Splunk integration with Splunk Cloud. Help! in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741877#M58415</link>
    <description>&lt;P&gt;Hi Will,&lt;/P&gt;&lt;P&gt;Yes, my Splunk index is named &lt;STRONG&gt;index=cloudflare&lt;/STRONG&gt;, and I haven't adjusted any of the default macros—they still point directly to this default index.&lt;/P&gt;&lt;P&gt;I'm still relatively new to Splunk, so I was a bit confused by the cloudflare:json sourcetype. Currently, I'm receiving logs directly into Splunk Cloud via Cloudflare Logpush, with the following sourcetypes automatically assigned:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Zero Trust&lt;/STRONG&gt; logs → cloudflare:access&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;DNS&lt;/STRONG&gt; logs → cloudflare:dns&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;HTTP&lt;/STRONG&gt; logs → cloudflare:http&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I don't have events explicitly assigned to cloudflare:json. Do you know if I need this sourcetype specifically, or is it okay that my logs are using the specific types mentioned above?&lt;/P&gt;&lt;P&gt;I am using Splunk cloud and received this logs via Cloudflare Logpush.&lt;/P&gt;&lt;P&gt;Thanks again for your help—I appreciate your patience!&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;AJH2000&lt;/P&gt;</description>
    <pubDate>Fri, 14 Mar 2025 22:27:52 GMT</pubDate>
    <dc:creator>AJH2000</dc:creator>
    <dc:date>2025-03-14T22:27:52Z</dc:date>
    <item>
      <title>Cloudflare app for Splunk integration with Splunk Cloud. Help!</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741846#M58412</link>
      <description>&lt;P&gt;Hello Splunk Community,&lt;/P&gt;&lt;P&gt;I have installed the &lt;STRONG&gt;Cloudflare for Splunk&lt;/STRONG&gt; app on &lt;STRONG&gt;Splunk Cloud&lt;/STRONG&gt; and have successfully configured &lt;STRONG&gt;Logpush&lt;/STRONG&gt; to send logs from Cloudflare to Splunk following the official instructions. I have verified that the logs are arriving correctly in Splunk using search queries like:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/app/4501" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/4501&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;index=cloudflare | head 10&lt;/PRE&gt;&lt;P&gt;I can see the logs in the search results, confirming that data ingestion is working. However, when I open the &lt;STRONG&gt;Cloudflare for Splunk&lt;/STRONG&gt; dashboards, they are empty, showing &lt;STRONG&gt;"No results found"&lt;/STRONG&gt;.&lt;/P&gt;&lt;H3&gt;&lt;STRONG&gt;I've checked the following topics.&lt;/STRONG&gt;&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Checked Data Arrival&lt;/STRONG&gt; - Logs are arriving correctly in Splunk (index=cloudflare contains data).&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Confirmed Sourcetype&lt;/STRONG&gt; - The logs are being assigned the expected sourcetype (cloudflare:access, cloudflare:network, etc.).&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Verified Time Range&lt;/STRONG&gt; - Made sure the dashboards are set to a broad time range (Last 24 hours or All Time).&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Checked Permissions&lt;/STRONG&gt; - Ensured that the user running the dashboards has access to the cloudflare index.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Examined Dashboard Searches&lt;/STRONG&gt; - Manually ran the searches used in the Cloudflare dashboards, but they returned no results.&lt;/LI&gt;&lt;/OL&gt;&lt;H3&gt;&lt;STRONG&gt;Questions:&lt;/STRONG&gt;&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;Has anyone faced this issue before?&lt;/LI&gt;&lt;LI&gt;Are there any known fixes or configuration adjustments required for the Cloudflare for Splunk dashboards to populate correctly?&lt;/LI&gt;&lt;LI&gt;Do I need to manually adjust field extractions or event types for the dashboards to work?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I appreciate any guidance or recommendations you can provide. Thanks in advance for your help!&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 17:02:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741846#M58412</guid>
      <dc:creator>AJH2000</dc:creator>
      <dc:date>2025-03-14T17:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare app for Splunk integration with Splunk Cloud. Help!</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741866#M58413</link>
      <description>&lt;P&gt;Can you please share one or more of the manual dashboard searches you ran?&amp;nbsp; It's possible they have errors that prevent data from showing.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 20:07:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741866#M58413</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-03-14T20:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare app for Splunk integration with Splunk Cloud. Help!</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741868#M58414</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276497"&gt;@AJH2000&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assume you havent adjusted the default macros in the app, so they are pointing to the same cloudflare index you mentioned (Which is the default).&lt;/P&gt;&lt;P&gt;There looks to be two types of search in the app dashboard - one which looks at the custom "cloudflare" datamodel and the other being adhoc searches against the cloudflare index.&lt;/P&gt;&lt;P&gt;The datamodel looks to have sourcetype=cloudflare:json - Can you confirm you have this?&lt;/P&gt;&lt;P&gt;Most of the sourcetype props in the app look to be search-time based, but there are some settings which are index-time parsing settings, such as line merging, truncation etc. You mentioned that you're using Splunk Cloud - is the data landing directly on Splunk Cloud or is it going via a HF beforehand? If so, please can you confirm if you have the TA installed on your HF(s) where the data lands?&lt;/P&gt;&lt;P&gt;If you could "open in search" one of the failing dashboard searches so that we can see whats going on then this might help further.&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 21:37:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741868#M58414</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-14T21:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare app for Splunk integration with Splunk Cloud. Help!</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741877#M58415</link>
      <description>&lt;P&gt;Hi Will,&lt;/P&gt;&lt;P&gt;Yes, my Splunk index is named &lt;STRONG&gt;index=cloudflare&lt;/STRONG&gt;, and I haven't adjusted any of the default macros—they still point directly to this default index.&lt;/P&gt;&lt;P&gt;I'm still relatively new to Splunk, so I was a bit confused by the cloudflare:json sourcetype. Currently, I'm receiving logs directly into Splunk Cloud via Cloudflare Logpush, with the following sourcetypes automatically assigned:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Zero Trust&lt;/STRONG&gt; logs → cloudflare:access&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;DNS&lt;/STRONG&gt; logs → cloudflare:dns&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;HTTP&lt;/STRONG&gt; logs → cloudflare:http&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I don't have events explicitly assigned to cloudflare:json. Do you know if I need this sourcetype specifically, or is it okay that my logs are using the specific types mentioned above?&lt;/P&gt;&lt;P&gt;I am using Splunk cloud and received this logs via Cloudflare Logpush.&lt;/P&gt;&lt;P&gt;Thanks again for your help—I appreciate your patience!&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;AJH2000&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 22:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741877#M58415</guid>
      <dc:creator>AJH2000</dc:creator>
      <dc:date>2025-03-14T22:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare app for Splunk integration with Splunk Cloud. Help!</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741918#M58422</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AJH2000_0-1742148204742.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38223i1CCD879C8B037729/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AJH2000_0-1742148204742.png" alt="AJH2000_0-1742148204742.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AJH2000_1-1742148288372.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38224iB61F4BCEF7706508/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AJH2000_1-1742148288372.png" alt="AJH2000_1-1742148288372.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AJH2000_2-1742148407841.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38225i5EF8330344699C01/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AJH2000_2-1742148407841.png" alt="AJH2000_2-1742148407841.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Mar 2025 18:08:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741918#M58422</guid>
      <dc:creator>AJH2000</dc:creator>
      <dc:date>2025-03-16T18:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare app for Splunk integration with Splunk Cloud. Help!</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741923#M58424</link>
      <description>&lt;P&gt;I asked for searches and you gave me screenshots of not searches.&amp;nbsp; How does that help you?&lt;/P&gt;</description>
      <pubDate>Sun, 16 Mar 2025 19:19:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741923#M58424</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-03-16T19:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare app for Splunk integration with Splunk Cloud. Help!</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741951#M58431</link>
      <description>&lt;P&gt;Hi sorry for the screenshot before, Is this what you asked me for?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AJH2000_0-1742221734258.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38234i5B78A98E495DEDB4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AJH2000_0-1742221734258.png" alt="AJH2000_0-1742221734258.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;TABLE width="575px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="123.656px"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;3/16/25&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3:52:18.000 PM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="450.344px"&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" title="" href="https://es.mide.splunkcloud.com/en-US/app/cloudflare/search?earliest=-30m%40m&amp;amp;latest=now&amp;amp;q=search%20index%3Dcloudflare%20sourcetype%3D%22cloudflare%3Aaccess%22&amp;amp;sid=1742156283.182755&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=#" target="_blank" rel="noopener nofollow noreferrer"&gt;[-]&lt;/A&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;AccountID:&amp;nbsp;aa8346d92df968cd0&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;BytesReceived:&amp;nbsp;0&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;BytesSent:&amp;nbsp;1260&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;ClientTCPHandshakeDurationMs:&amp;nbsp;0&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;ClientTLSCipher:&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;ClientTLSHandshakeDurationMs:&amp;nbsp;0&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;ClientTLSVersion:&amp;nbsp;none&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;ConnectionCloseReason:&amp;nbsp;PROXY_CONN_REFUSED&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;ConnectionReuse:&amp;nbsp;false&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;DestinationTunnelID:&amp;nbsp;8fcb-eb9c3e12&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;DetectedProtocol:&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;DeviceID:&amp;nbsp;12201bc8598d&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;DeviceName:&amp;nbsp;Dev&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;EgressColoName:&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;EgressIP:&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;EgressPort:&amp;nbsp;52772&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;EgressRuleID:&amp;nbsp;00000000-0000-0000-0000-000000000000&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;EgressRuleName:&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;Email:&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;IngressColoName:&amp;nbsp;ATL&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;Offramp:&amp;nbsp;CFD_TUNNEL&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;OriginIP:&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;OriginPort:&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;OriginTLSCertificateIssuer:&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;OriginTLSCertificateValidationResult:&amp;nbsp;NONE&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;OriginTLSCipher:&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;OriginTLSHandshakeDurationMs:&amp;nbsp;0&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;OriginTLSVersion:&amp;nbsp;none&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;Protocol:&amp;nbsp;UDP&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;RuleEvaluationDurationMs:&amp;nbsp;0&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;SessionEndTime:&amp;nbsp;2025-03-16T19:50:03Z&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;SessionID:&amp;nbsp;26421ab3fd000045601a91c400000001&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;SessionStartTime:&amp;nbsp;2025-03-16T19:50:03Z&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;SourceIP:&amp;nbsp;120.121.150.25&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;SourceInternalIP:&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;SourcePort:&amp;nbsp;52772&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;UserID:&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;VirtualNetworkID:&amp;nbsp;4497-9733-932d3b6b4e74&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 17 Mar 2025 10:29:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741951#M58431</guid>
      <dc:creator>AJH2000</dc:creator>
      <dc:date>2025-03-17T10:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare app for Splunk integration with Splunk Cloud. Help!</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741954#M58432</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AJH2000_0-1742222037350.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38235iED0762338ADC9954/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AJH2000_0-1742222037350.png" alt="AJH2000_0-1742222037350.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AJH2000_1-1742222051544.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38236iF9EA8AB771B8C291/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AJH2000_1-1742222051544.png" alt="AJH2000_1-1742222051544.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 10:34:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741954#M58432</guid>
      <dc:creator>AJH2000</dc:creator>
      <dc:date>2025-03-17T10:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare app for Splunk integration with Splunk Cloud. Help!</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741958#M58433</link>
      <description>&lt;P&gt;The first search is looking for non-empty AppDomain fields, but the second search shows the events do not have an AppDomain field at all.&amp;nbsp; That will keep the dashboard from displaying data.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 11:54:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741958#M58433</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-03-17T11:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare app for Splunk integration with Splunk Cloud. Help!</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741981#M58434</link>
      <description>&lt;P&gt;Okay, thanks.&lt;/P&gt;&lt;P&gt;In this case, what steps do you recommend I take, and what would be the best way for me to modify my dashboard? What steps should I follow to find a solution?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 14:40:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/741981#M58434</guid>
      <dc:creator>AJH2000</dc:creator>
      <dc:date>2025-03-17T14:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare app for Splunk integration with Splunk Cloud. Help!</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/742016#M58439</link>
      <description>&lt;P&gt;Investigate the data source to determine why it does not have the AppDomain field.&amp;nbsp; Perhaps it's not present and perhaps it's present under a different name.&amp;nbsp; For the latter, add an &lt;FONT face="courier new,courier"&gt;EVAL&lt;/FONT&gt; or &lt;FONT face="courier new,courier"&gt;FIELDALIAS&lt;/FONT&gt; definition to map the field to the expected name.&lt;/P&gt;&lt;P&gt;I advise against changing third-party dashboards.&amp;nbsp; Once you do that, it becomes your responsibility to keep the dashboard up-to-date.&amp;nbsp; Updating the app will not update the dashboard because it will be a local change that overrides the default that ships with the app.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 17:08:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Cloudflare-app-for-Splunk-integration-with-Splunk-Cloud-Help/m-p/742016#M58439</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-03-17T17:08:55Z</dc:date>
    </item>
  </channel>
</rss>

