All Apps and Add-ons

How to filter Palo Alto Web Activity Report on source user only

chuckne
New Member

I am trying to generate a Web Activity Report on a per user basis.
I have tried removing the quotes (") from the end of log.user= and from the Token Suffix field. I still cannot get a search to complete using only the user name (No Results Found), even though the user is ID'd in the firewalls and I see the traffic there.
Furthermore, if I look at the Traffic Dashboard, I do see where users are identified in the default "Source User" panel, so the Palo Alto App is able to pull that information, why then does it not work in the Web Activity Report or trying to filter in the Traffic Report by Source User ?

Any assistance would be greatly appreciated.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...