Skip to content
This repository was archived by the owner on Dec 14, 2024. It is now read-only.

Commit 92f83af

Browse files
authored
fix(app): Add missing summariesonly to web_activity.xml
PR #240
1 parent 715eebb commit 92f83af

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

SplunkforPaloAltoNetworks/default/data/ui/views/web_activity.xml

+2-2
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
<form version="1.1">
22
<label>Web Activity</label>
33
<search id="basesearch">
4-
<query>| tstats values(log.flags) AS log.flags, count FROM datamodel=pan_firewall WHERE nodename="log.url" $serial$ $vsys$ $src_ip$ $dest_name$ "$user|s$" $app$ $content$ $category$ $action$ GROUPBY _time log.dest_name log.app:category log.app log.action log.content_type log.vendor_action | rename log.* AS * </query>
4+
<query>| tstats summariesonly=t values(log.flags) AS log.flags, count FROM datamodel=pan_firewall WHERE nodename="log.url" $serial$ $vsys$ $src_ip$ $dest_name$ "$user|s$" $app$ $content$ $category$ $action$ GROUPBY _time log.dest_name log.app:category log.app log.action log.content_type log.vendor_action | rename log.* AS * </query>
55
<earliest>$time.earliest$</earliest>
66
<latest>$time.latest$</latest>
77
</search>
@@ -307,7 +307,7 @@ file_name=$row.file_name|s$&amp;earliest=$time.earliest$&amp;latest=$time.latest
307307
<title>Decrypted Traffic</title>
308308
<table>
309309
<search>
310-
<query>| tstats values(log.flags) AS log.flags, values(log.user) AS log.user, count FROM datamodel=pan_firewall WHERE nodename="log.url" GROUPBY _time log.src_ip log.dest_name log.category log.app log.action log.content_type log.vendor_action | rename log.* AS * | search flags="decrypted" | table _time src_ip user dest_name category app flags count</query>
310+
<query>| tstats summariesonly=t values(log.flags) AS log.flags, values(log.user) AS log.user, count FROM datamodel=pan_firewall WHERE nodename="log.url" GROUPBY _time log.src_ip log.dest_name log.category log.app log.action log.content_type log.vendor_action | rename log.* AS * | search flags="decrypted" | table _time src_ip user dest_name category app flags count</query>
311311
<earliest>-60m</earliest>
312312
<latest>now</latest>
313313
<sampleRatio>1</sampleRatio>

0 commit comments

Comments
 (0)