Hello everyone,
I'm looking to make a simple search form with a few text inputs and a drop-down box to search for firewall logs. I would like the output to be shown as events. My company has Palo Alto and Cisco ASA firewalls. All logs are sent to splunk.
Input text boxes would be:
1.) Source 2.) Destination 3.) Port
Drop-down box would be:
1.) allow 2.) not equal to allow
**For the text inputs I would like all of the fields to be optional in case I don't want to use all 3**
Is there an easy way to accomplish this?
Thank you in advance.
Start by loading the examples app from splunkbase https://splunkbase.splunk.com/app/1603/
There are lots of examples of how to build dashboards include tables and inputs