All Apps and Add-ons

How to add a filter to a dashboard in Palo Alto Networks App for Splunk?

heathramos
Path Finder

I was wondering if it was possible to add a filter to one of the dashboards in the Palo Alto Networks App for Splunk?

I want to be able to filter the traffic dashboard by src_zone.

I can, of course, drilldown and filter within the search but I want the filter to be on the dashboard.

I have never created or altered a dashboard before.

0 Karma
1 Solution

woodcock
Esteemed Legend

I would make a copy of it and edit that. Go to Settings -> Searches, Reports, and Alerts -> select your app in the App Context listbox in the upper-left -> in the search bar on the upper-right, search for your dashboard, when you find it -> Clone -> then click Run -> then Edit and go from there.

View solution in original post

0 Karma

woodcock
Esteemed Legend

I would make a copy of it and edit that. Go to Settings -> Searches, Reports, and Alerts -> select your app in the App Context listbox in the upper-left -> in the search bar on the upper-right, search for your dashboard, when you find it -> Clone -> then click Run -> then Edit and go from there.

0 Karma

heathramos
Path Finder

I can't find that dashboard in Settings -> Searches, Reports, and Alerts

If I go back to the dashboard within the app and select edit permissions, I get the following info:

Dashboard: Traffic Dashboard
Owner: nobody
App: SplunkforPaloAltoNetworks

Not sure where to find it.

0 Karma

woodcock
Esteemed Legend

When you run the dashboard, take the string on the URL bar from the last / through to the ? and that is the name of the dashboard. Then go to Searches, Reports, and Alerts and paste that name string in the search box.

Alternatively, replace everything after the ? with showsource=true and copy the XML and then just paste it into your own "new" dashboard.

0 Karma

heathramos
Path Finder

I was able to clone it, find the cloned dashboard and alter the XML but how do you add it to the menus so I can run the customized version within the app?

0 Karma

heathramos
Path Finder

nevermind...got that to work

had to add the view to the user interface

thanks for the help

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...