All Apps and Add-ons

How to filter Palo Alto Web Activity Report on source user only

chuckne
New Member

I am trying to generate a Web Activity Report on a per user basis.
I have tried removing the quotes (") from the end of log.user= and from the Token Suffix field. I still cannot get a search to complete using only the user name (No Results Found), even though the user is ID'd in the firewalls and I see the traffic there.
Furthermore, if I look at the Traffic Dashboard, I do see where users are identified in the default "Source User" panel, so the Palo Alto App is able to pull that information, why then does it not work in the Web Activity Report or trying to filter in the Traffic Report by Source User ?

Any assistance would be greatly appreciated.

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...