We are trying to determine the best way to provide a user activity report from our Palo Alto logs and are having trouble with the appropriate Splunk search. Something to show "total bytes for each destination hostname grouped by user over a nominated time period" . Could anyone provide any advice on how that search could be written? Obviously we are rather new to Splunk but have the search basics in hand, just not more advanced search syntax.
We are using Splunk 6.5.2, Palo Alto Networks Add-on for Splunk 3.7.1 and Palo Alto Networks App for Splunk 5.3.1.
... View more