Dashboards & Visualizations

Zscaler - Splunk : Logs aren't shown

sarashafek
Explorer

Hi,

I have a Nanalog Streaming Service (NSS) from Zscaler that I have connected to Splunk. 
The problem is it doesn't show any data on the dashboard. But if I look into 'search' , there is data.

sarashafek_0-1700820326631.png

sarashafek_1-1700820478877.png

This is the feed output format I have configured on the Zscaler Admin Portal for my splunk feed :

"%s{time}","%s{login}","%s{proto}","%s{eurl}","%s{action}","%s{appname}","%s{appclass}","%d{reqsize}","%d{respsize}","%s{urlclass}","%s{urlsupercat}","%s{urlcat}","%s{malwarecat}","%s{threatname}","%d{riskscore}","%s{dlpeng}","%s{dlpdict}","%s{location}","%s{dept}","%s{cip}","%s{sip}","%s{reqmethod}","%s{respcode}","%s{ua}","%s{ereferer}","%s{ruletype}","%s{rulelabel}","%s{contenttype}","%s{unscannabletype}","%s{deviceowner}","%s{devicehostname}","%s{keyprotectiontype}"

Any suggestions on how I can further troubleshoot?

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I don't know this app but first thing I'd do with any such issue would be to do "open in search" on those panels and see what is the underlying search and try to see why it's not working properly. Maybe it expects other data than you have. Maybe it searches from a wrong place....

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...