All Apps and Add-ons

Global protect dashboard empty

Iwdavies
Path Finder

I have some of the dashboards showing information and some do not.  Currently I'm working on getting the global protect dashboard to show information.

While I do see global protect listed in some of the log files while looking at Pan:system; I do not see "log_subtype="globalprotect"".

I do see the following log subtypes:

vpn

general

auth

userid

url-filtering

 

I unfortunately have no idea how to tell the system how to parse the data for globalprotect.

 

Ian

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Are you Splunking your Global Protect data?  If not, then it will never appear on a dashboard until you do.

It's possible your data is formatted differently from what is expected by the dashboard.  That can happen has products change over time.  Perhaps log_subtype=vpn is what you need.  Clone the dashboard and modify it to fit your data.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Iwdavies
Path Finder

Unfortunately,  the vpn log type is for our point-to-point tunnels and not GlobalProtect 😞

 

I do see global protect data if I look at the data directly, I just don't see it populating the dashboard .

 

Ian

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you can see the data using manual searches then you are halfway there.  Clone the GP dashboard and modify it to use your manual searches.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...