All Apps and Add-ons

Global protect dashboard empty

Iwdavies
Path Finder

I have some of the dashboards showing information and some do not.  Currently I'm working on getting the global protect dashboard to show information.

While I do see global protect listed in some of the log files while looking at Pan:system; I do not see "log_subtype="globalprotect"".

I do see the following log subtypes:

vpn

general

auth

userid

url-filtering

 

I unfortunately have no idea how to tell the system how to parse the data for globalprotect.

 

Ian

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Are you Splunking your Global Protect data?  If not, then it will never appear on a dashboard until you do.

It's possible your data is formatted differently from what is expected by the dashboard.  That can happen has products change over time.  Perhaps log_subtype=vpn is what you need.  Clone the dashboard and modify it to fit your data.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Iwdavies
Path Finder

Unfortunately,  the vpn log type is for our point-to-point tunnels and not GlobalProtect 😞

 

I do see global protect data if I look at the data directly, I just don't see it populating the dashboard .

 

Ian

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you can see the data using manual searches then you are halfway there.  Clone the GP dashboard and modify it to use your manual searches.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...