<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Configure Palo Alto Add-On (Splunk_TA_paloalto 3.5.2) for Enterprise Security 4.0 (Splunk Enteprise 6.3.3) on my Linux environment. in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251066#M28754</link>
    <description>&lt;P&gt;On the HF your inputs can be installed here:&lt;BR /&gt;
$SPLUNK_HOME/etc/apps/Splunk_TA_paloalto/local/inputs.conf&lt;/P&gt;

&lt;P&gt;Since you are using 3.5.2 you can use the 5.x stanza.&lt;/P&gt;

&lt;P&gt;Have you tried this already?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 09:28:19 GMT</pubDate>
    <dc:creator>ndesignhouse</dc:creator>
    <dc:date>2020-09-29T09:28:19Z</dc:date>
    <item>
      <title>How to Configure Palo Alto Add-On (Splunk_TA_paloalto 3.5.2) for Enterprise Security 4.0 (Splunk Enteprise 6.3.3) on my Linux environment.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251063#M28751</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I am trying to setup Palo Alto Add-On (Splunk_TA_paloalto 3.5.2) for Enterprise Security 4.0 (Splunk Enteprise 6.3.3). I already have the Palo Alto logs sending to the Forwarder. I have installed the Splunk_TA_paloalto (3.5.2) using the directions provided by Splunk for Palo Alto Networks "&lt;A href="http://pansplunk.readthedocs.org/en/latest/getting_started.html#step-1-install-the-app-and-add-on" target="_blank"&gt;http://pansplunk.readthedocs.org/en/latest/getting_started.html#step-1-install-the-app-and-add-on&lt;/A&gt;" but it doesn't really provide a detailed instruction on how to configure the required files on the Forwarder and the Indexer. If I do not use the Palo Alto App, which inputs.conf do I follow? How do I create the pan_logs Indexes? Do I create the input using the 5.x or 4.x stanza? Can someone please advise or help?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251063#M28751</guid>
      <dc:creator>jl_Splunk</dc:creator>
      <dc:date>2020-09-29T09:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Palo Alto Add-On (Splunk_TA_paloalto 3.5.2) for Enterprise Security 4.0 (Splunk Enteprise 6.3.3) on my Linux environment.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251064#M28752</link>
      <description>&lt;P&gt;Are you using the universal forwarder?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 14:38:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251064#M28752</guid>
      <dc:creator>ndesignhouse</dc:creator>
      <dc:date>2016-04-20T14:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Palo Alto Add-On (Splunk_TA_paloalto 3.5.2) for Enterprise Security 4.0 (Splunk Enteprise 6.3.3) on my Linux environment.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251065#M28753</link>
      <description>&lt;P&gt;Hi @ndesignhouse, we are not using the UF. We setup PA server to send directly to the HF.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 21:57:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251065#M28753</guid>
      <dc:creator>jl_Splunk</dc:creator>
      <dc:date>2016-04-20T21:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Palo Alto Add-On (Splunk_TA_paloalto 3.5.2) for Enterprise Security 4.0 (Splunk Enteprise 6.3.3) on my Linux environment.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251066#M28754</link>
      <description>&lt;P&gt;On the HF your inputs can be installed here:&lt;BR /&gt;
$SPLUNK_HOME/etc/apps/Splunk_TA_paloalto/local/inputs.conf&lt;/P&gt;

&lt;P&gt;Since you are using 3.5.2 you can use the 5.x stanza.&lt;/P&gt;

&lt;P&gt;Have you tried this already?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:28:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251066#M28754</guid>
      <dc:creator>ndesignhouse</dc:creator>
      <dc:date>2020-09-29T09:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Palo Alto Add-On (Splunk_TA_paloalto 3.5.2) for Enterprise Security 4.0 (Splunk Enteprise 6.3.3) on my Linux environment.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251067#M28755</link>
      <description>&lt;P&gt;On the HF, your inputs can be installed here:&lt;BR /&gt;
$SPLUNK_HOME/etc/apps/Splunk_TA_paloalto/local/inputs.conf&lt;/P&gt;

&lt;P&gt;Since you are using 3.5.2 you can use the 5.x stanza.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[udp://514]
sourcetype = pan:log
no_appending_timestamp = true
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:28:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251067#M28755</guid>
      <dc:creator>ndesignhouse</dc:creator>
      <dc:date>2020-09-29T09:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Palo Alto Add-On (Splunk_TA_paloalto 3.5.2) for Enterprise Security 4.0 (Splunk Enteprise 6.3.3) on my Linux environment.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251068#M28756</link>
      <description>&lt;P&gt;Does it have to be in UDP stanza? I have it on monitor because I have setup my HF server to save events received from PA Server to a specific directory.&lt;/P&gt;

&lt;P&gt;I notice a latest version so I have installed Splunk_TA_paloalto 3.6 on my Deployer, HF, Indexer and SearchHead.&lt;/P&gt;

&lt;P&gt;The below is what I have on my HF only. Currently, I still do not see any indexed data on the Indexer server. Am I missing some config steps on the Indexer or SearchHead server?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///home/splunk/remote/ip/*.log]
disabled = false
host_segment = 4
sourcetype = pan:log
no_appending_timestamp = true
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:32:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251068#M28756</guid>
      <dc:creator>jl_Splunk</dc:creator>
      <dc:date>2020-09-29T09:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Palo Alto Add-On (Splunk_TA_paloalto 3.5.2) for Enterprise Security 4.0 (Splunk Enteprise 6.3.3) on my Linux environment.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251069#M28757</link>
      <description>&lt;P&gt;Thanks for help &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/162068"&gt;@ndesignhouse&lt;/a&gt; , I am able to search for the events now using the search string:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* sourcetype=pan*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The only difference from yours is that I am using the monitor stanza and using the Splunk_TA_paloalto 3.6 instead of 3.5.2.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///home/splunk/remote/ipaddress*/*.log]
disabled = false
host_segment = 4
sourcetype = pan:log
no_appending_timestamp = true
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:32:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251069#M28757</guid>
      <dc:creator>jl_Splunk</dc:creator>
      <dc:date>2020-09-29T09:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Palo Alto Add-On (Splunk_TA_paloalto 3.5.2) for Enterprise Security 4.0 (Splunk Enteprise 6.3.3) on my Linux environment.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251070#M28758</link>
      <description>&lt;P&gt;Yes you can use monitor. I use monitor as well. You won't need the no_appending_timestamp as that is an attribute for UDP only.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:28:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251070#M28758</guid>
      <dc:creator>ndesignhouse</dc:creator>
      <dc:date>2020-09-29T09:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Palo Alto Add-On (Splunk_TA_paloalto 3.5.2) for Enterprise Security 4.0 (Splunk Enteprise 6.3.3) on my Linux environment.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251071#M28759</link>
      <description>&lt;P&gt;Glad i could help : )&lt;/P&gt;</description>
      <pubDate>Sat, 23 Apr 2016 02:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Configure-Palo-Alto-Add-On-Splunk-TA-paloalto-3-5-2-for/m-p/251071#M28759</guid>
      <dc:creator>ndesignhouse</dc:creator>
      <dc:date>2016-04-23T02:36:16Z</dc:date>
    </item>
  </channel>
</rss>

