All Apps and Add-ons

Why aren't the Palo Alto App and Palo Alto Add-on transforming global protect user?

aarongensch
Engager

Hi
We have noticed that within the Palo Alto app-->Activity-GlobalProtect that "user" is always unknown.

In the transforms:

[extract_globalprotect_user]
SOURCE_KEY =  description
REGEX = User name: (?[^,]+)

[extract_globalprotect_ip]
SOURCE_KEY =  description
REGEX = Private IP: (?[^,]+)

The user should be extracted out of the description.

Within the props.conf in traffic section
EVAL-user = coalesce(src_user,dest_user,"unknown")

has anyone found this issue and resolved it?

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...