All Apps and Add-ons

Adding xauthuser to datamodel

jairjr
Path Finder

I tried to add the xauthuser field to the data model ftnt_fos and after that I get no results any more. Did I break it?

The xauthuser field carries the username that connected to the firewall using an ipsec tunnel, it's a critical field for the vpn dashboard.

0 Karma

jairjr
Path Finder

In the Splunk web ui I went to Settings/Datamodels, then opened the "Fortinet FOS Log" datamodel:

  • I disabled acceleration otherwise it does not allow me to edit the datamodel
  • In the "Firewall Logs" item I added a new extracted field named xauthuser with type string.
  • Enabled acceleration again.

Now when I go to any Fortigate pre-built dashboard I get "No results".

0 Karma

jerryzhao
Contributor

what's the datamodel acceleration progress?

0 Karma

jairjr
Path Finder

93%, now the dashboards are working. I think I just didn't wait enough, thank you for your help.

0 Karma

jerryzhao
Contributor

what file are you changing? the datamodel should be defined in SplunkAppForFortinet/default/data/models/ftnt_fos.json
what are your changes? please paste it here.
which dashboard query on vpn are you adding/customizing?

0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...