All Apps and Add-ons

How to add a filter to a dashboard in Palo Alto Networks App for Splunk?

heathramos
Path Finder

I was wondering if it was possible to add a filter to one of the dashboards in the Palo Alto Networks App for Splunk?

I want to be able to filter the traffic dashboard by src_zone.

I can, of course, drilldown and filter within the search but I want the filter to be on the dashboard.

I have never created or altered a dashboard before.

0 Karma
1 Solution

woodcock
Esteemed Legend

I would make a copy of it and edit that. Go to Settings -> Searches, Reports, and Alerts -> select your app in the App Context listbox in the upper-left -> in the search bar on the upper-right, search for your dashboard, when you find it -> Clone -> then click Run -> then Edit and go from there.

View solution in original post

0 Karma

woodcock
Esteemed Legend

I would make a copy of it and edit that. Go to Settings -> Searches, Reports, and Alerts -> select your app in the App Context listbox in the upper-left -> in the search bar on the upper-right, search for your dashboard, when you find it -> Clone -> then click Run -> then Edit and go from there.

0 Karma

heathramos
Path Finder

I can't find that dashboard in Settings -> Searches, Reports, and Alerts

If I go back to the dashboard within the app and select edit permissions, I get the following info:

Dashboard: Traffic Dashboard
Owner: nobody
App: SplunkforPaloAltoNetworks

Not sure where to find it.

0 Karma

woodcock
Esteemed Legend

When you run the dashboard, take the string on the URL bar from the last / through to the ? and that is the name of the dashboard. Then go to Searches, Reports, and Alerts and paste that name string in the search box.

Alternatively, replace everything after the ? with showsource=true and copy the XML and then just paste it into your own "new" dashboard.

0 Karma

heathramos
Path Finder

I was able to clone it, find the cloned dashboard and alter the XML but how do you add it to the menus so I can run the customized version within the app?

0 Karma

heathramos
Path Finder

nevermind...got that to work

had to add the view to the user interface

thanks for the help

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...