- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/5ac22/5ac221a5cc2eb369510974287ba4c81004ff5bcb" alt="jwalzerpitt jwalzerpitt"
We have ES up and running and I'm starting to review the various Security Domains and relevant dashboards/reports.
For Security Domain -- Network -- Web Center there is a widget of 'Events Over Time By Status' that when I send to a search returns values other than HTTP status codes (200, 401, etc).
I do a pivot of the web data model and select 'status' and 'sourcetype' and I see the pan:threat sourcetype from our Palo Alto logs included with values that do not correspond to HTTP status codes.
Where would, or how would I go about excluding the pan:threat sourcetype from either the search, or from 'status' altogether?
The search is as follows:
| `tstats` count from datamodel=Web.Web where * by _time,Web.status span=10m
| timechart minspan=10m useother=`useother` count by Web.status
| `drop_dm_object_name("Web")`
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/00ea7/00ea728ddd59db76fcdafc5039051fc288625212" alt="richgalloway richgalloway"
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
I'm tempted to modify the CS to exclude the PAN events.
| `tstats` count from datamodel=Web.Web where NOT sourcetype=pan:threat by _time,Web.status span=10m
| timechart minspan=10m useother=`useother` count by Web.status
| `drop_dm_object_name("Web")`
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/00ea7/00ea728ddd59db76fcdafc5039051fc288625212" alt="richgalloway richgalloway"
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
I'm tempted to modify the CS to exclude the PAN events.
| `tstats` count from datamodel=Web.Web where NOT sourcetype=pan:threat by _time,Web.status span=10m
| timechart minspan=10m useother=`useother` count by Web.status
| `drop_dm_object_name("Web")`
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/5ac22/5ac221a5cc2eb369510974287ba4c81004ff5bcb" alt="jwalzerpitt jwalzerpitt"
Thx Rich - worked perfectly
data:image/s3,"s3://crabby-images/2f34b/2f34b8387157c32fbd6848ab5b6e4c62160b6f87" alt=""