<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suggestions for Splunk Search/Report in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/suggestions-for-splunk-search-report/m-p/176407#M55172</link>
    <description>&lt;P&gt;Thanks, I haven't created any datasets, just done specific reports based on the criteria I've been interested in seeing regularly. &amp;nbsp;I'll have a look at the dataset creation portion and see what I need to do. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My biggest problem is meshing the palo alto on the perimeter and the ASA(s) that operate the DMZ. &amp;nbsp;Between the 2 of them they generate an enormous amount of material, especially with the multiple entries that VPN access creates. &amp;nbsp;It's really pretty overwhelming trying to figure out what is noise and what is something to be concerned about. &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Sep 2017 19:30:18 GMT</pubDate>
    <dc:creator>davehaertel</dc:creator>
    <dc:date>2017-09-13T19:30:18Z</dc:date>
    <item>
      <title>Suggestions for Splunk Search/Report</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suggestions-for-splunk-search-report/m-p/176327#M55154</link>
      <description>&lt;P&gt;We have the Palo Alto app for Splunk logging everything correctly, I'm basically looking for suggestions on solid search reports to eliminate most of the noise. &amp;nbsp;I've been combing through some of the Splunk forum posts but nothing jumping out at me so far. Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2017 13:46:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suggestions-for-splunk-search-report/m-p/176327#M55154</guid>
      <dc:creator>davehaertel</dc:creator>
      <dc:date>2017-09-13T13:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions for Splunk Search/Report</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suggestions-for-splunk-search-report/m-p/176383#M55163</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71981"&gt;@davehaertel&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would really recommend diving into creating custom datasets and filtering for anything that you really care about that way, this also allows you to schedule the reports. For example I have a dataset configured to look at my threat logs and gather all of action and client_ip information so that I can quickly see if there is any single IP that is generating a large amount of threats or DoS policy alerts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2017 16:28:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suggestions-for-splunk-search-report/m-p/176383#M55163</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-13T16:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions for Splunk Search/Report</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suggestions-for-splunk-search-report/m-p/176407#M55172</link>
      <description>&lt;P&gt;Thanks, I haven't created any datasets, just done specific reports based on the criteria I've been interested in seeing regularly. &amp;nbsp;I'll have a look at the dataset creation portion and see what I need to do. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My biggest problem is meshing the palo alto on the perimeter and the ASA(s) that operate the DMZ. &amp;nbsp;Between the 2 of them they generate an enormous amount of material, especially with the multiple entries that VPN access creates. &amp;nbsp;It's really pretty overwhelming trying to figure out what is noise and what is something to be concerned about. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2017 19:30:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suggestions-for-splunk-search-report/m-p/176407#M55172</guid>
      <dc:creator>davehaertel</dc:creator>
      <dc:date>2017-09-13T19:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions for Splunk Search/Report</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suggestions-for-splunk-search-report/m-p/176416#M55173</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71981"&gt;@davehaertel&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;In my experiance, and mind you I'm no expert at Splunk, Splunk is a great tool&amp;nbsp;&lt;EM&gt;if you know what you are looking for&lt;/EM&gt; and that's about it. Just reviewing the logs you'll find a ton of stuff that doesn't really hold any value or doesn't really matter.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2017 20:49:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suggestions-for-splunk-search-report/m-p/176416#M55173</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-13T20:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions for Splunk Search/Report</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suggestions-for-splunk-search-report/m-p/176418#M55174</link>
      <description>&lt;P&gt;I agree completely. &amp;nbsp;If you aren't careful you can drown in meaningless data, looking for that tiny little bit that actually indicates that there's a hole that needs to be plugged lol. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I spend an hour every morning just going through the windows logs and I think I have that finally narrowed down to just the basic stuff that I'm concerned about, but moving forward to the Cisco and Palo Alto additions, I'm going to easily have 2 hours a day just going through my checklists. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oh well time to ask for an assistant LOL!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2017 20:58:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suggestions-for-splunk-search-report/m-p/176418#M55174</guid>
      <dc:creator>davehaertel</dc:creator>
      <dc:date>2017-09-13T20:58:15Z</dc:date>
    </item>
  </channel>
</rss>

