Dashboards & Visualizations

why is my prebuilt panel included with Splunk add-on for Symantec DLP returning no results?

splunkbeginner
Engager

I make sure the search results can return the results which is within 24h period as expected.
alt text

I am trying to use the prebuilt panel included with Splunk add-on for Symantec DLP - "symantec_dlp_top_10_incident_senders_in_last_24h" to show the particular intertesed senders who caused the incidents.

The following is the context of prebuilt panel of "symantec_dlp_top_10_incident_senders_in_last_24h". I expect they shall be correct, without having any further modification?

  <query>sourcetype="symantec:dlp:syslog" earliest=-24h  | top limit=10 showperc=false sender</query>

Then i added the prebuilt panel to dashboards in order to view the results, but no luck.
alt text

In fact, I tried all the prebuilt panels included with Splunk add-on for Symantec DLP as follows.

symantec_dlp_activities_by_action_in_last_24h
symantec_dlp_severity_distribution_in_last_24h
antec_dlp_top_10_incident_senders_in_last_24h
antec_dlp__severity_distribution_in_last_24h

The above panels are found in > Splunk Web > Settings > User interface > Prebuilt panels. Again I expect they shall be correct, without having any further modification?

FYI: As per the official instructions, I have specified the following variables to extract from my Symantec DLP system and send them to Splunk.

Message = ID: $INCIDENT_ID$, Policy Violated: $POLICY$, Rules: $POLICY_RULES$, Count: $MATCH_COUNT$, Protocol: $PROTOCOL$, Recipient: $RECIPIENTS$, Sender: $SENDER$, Severity: $SEVERITY$, Subject: $SUBJECT$, Target: $TARGET$, Filename: $FILE_NAME$, Blocked: $BLOCKED$, Endpoint: $ENDPOINT_MACHINE$

Tags (1)
0 Karma
1 Solution

lakshman239
Influencer

Pls check my answer to one of your other question.

You need to install https://splunkbase.splunk.com/app/1314/ to see the dashboard/pre-built panels in addition to installing the TA - https://splunkbase.splunk.com/app/3029/

https://docs.splunk.com/Documentation/AddOns/released/SymantecDLP/Installationoverview

Also, if you use diff sourcetype/index, you may need to adjust them to match with DLP Add-on/app.

View solution in original post

0 Karma

lakshman239
Influencer

Pls check my answer to one of your other question.

You need to install https://splunkbase.splunk.com/app/1314/ to see the dashboard/pre-built panels in addition to installing the TA - https://splunkbase.splunk.com/app/3029/

https://docs.splunk.com/Documentation/AddOns/released/SymantecDLP/Installationoverview

Also, if you use diff sourcetype/index, you may need to adjust them to match with DLP Add-on/app.

0 Karma

lakshman239
Influencer

If this has helped, can you pls accept the answer to close tracking?

0 Karma

splunkbeginner
Engager

thank you for your answer which really helps.

0 Karma

splunkbeginner
Engager

alt text

Please ignore the second photo, and refer to this one instead.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...