First of all, this app is awesome. Thanks Monzy for creating & updating it.
I'm playing with this app a little and made one change for my environment:
for VPN profile:
eventtype=cisco_vpn_start $user$ | streamstats dc(src) by user</query>
There is probably some sort of datamodel / tstats search, but I'm not smart enough to figure it out right now.
Hey, you coming back to this post or what?
Does this help?
$splunk_home/etc/apps/DBIR_splunk_app/appserver/static/html/dbir_help_basic.html
Hi @niemesrw
Is there a specific question you're asking the community for help with?