Reporting

Pivot with Palo Alto Data

ronaldlb
Explorer

HI

Can anyone help me with pivot tables in Splunk I am trying to get Palo Alto data to work but it does not give me the report I need. I am looking for user name with time they have visited website and session.

I have this in palo alto but I want a dashboard type experience so I know splunk can do it.

Regards

Ronald

Tags (3)
0 Karma
1 Solution

btorresgil
Builder

The Splunk for Palo Alto Networks App has a data model and dashboards built in. There is a dashboard called Web Activity Report that has the websites, you could easily add users to the panels. Or you can use a pivot to build your own by clicking 'Settings' at the top right, then 'Datamodel', select the Palo Alto Networks Logs data model, and click 'Pivot'. Here you can build a pivot with the fields 'user' and 'dst_hostname' to get the report you want.

Splunk for Palo Alto Networks App:

http://apps.splunk.com/app/491/

View solution in original post

btorresgil
Builder

The Splunk for Palo Alto Networks App has a data model and dashboards built in. There is a dashboard called Web Activity Report that has the websites, you could easily add users to the panels. Or you can use a pivot to build your own by clicking 'Settings' at the top right, then 'Datamodel', select the Palo Alto Networks Logs data model, and click 'Pivot'. Here you can build a pivot with the fields 'user' and 'dst_hostname' to get the report you want.

Splunk for Palo Alto Networks App:

http://apps.splunk.com/app/491/

ronaldlb
Explorer

Thank you for your help.

0 Karma

splunker12er
Motivator

Pivot option is very much helpful to present or generate a dashboard or statistical report from a data source.
You first need to create a proper data model before you pivot. (field extractions, automatic fields, etc..)
Try the sample pivot data models available in your Search application , so you will able to grasp some ideas on its usage.
you have options to transpose the data, stats , etc.. things you are deriving from search query.. you can able to do it graphically in pivot.

0 Karma

ppablo
Retired

Hi Ronald,

Have you been using the app Splunk for Palo Alto Networks?
http://apps.splunk.com/app/491/

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...