All Apps and Add-ons

Palo Alto Networks App for Splunk: Multi-tenant question

BrendanCO
Path Finder

Hello! I'm trying to edit a dashboard and add an input to filter by "dvc_host". We are now bringing in multiple PANs and I'd like to be able to look at these dashboards by each individual PAN.

Looking at the input "src_ip" I see the format looks like this:
http://imgur.com/MaikAM7

Now, I try to add the input "dvc_host" and mirror the input with the appropriate field name:
http://imgur.com/h4YRL2t

And it doesn't work.

A little help, please? I had someone try to answer this for me previously but I couldn't figure out what they were instructing me to do.

0 Karma

BrendanCO
Path Finder

Never mind, folks! Just got an email from Palo saying that their next release will include functionality to isolate dashboards to individual PANs. Should be ready in a few months, they said. Problem nearly solved! 🙂

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...