<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Traps - No Wildfire data in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Traps-No-Wildfire-data/m-p/419720#M51170</link>
    <description>&lt;P&gt;The pan_wildfire event type comes from Palo Alto Networks Firewall logs. Typically it is a THREAT log type with a subtype of wildfire. The wildfire dashboard will get populated when Firewall logs are being sent to Splunk.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jun 2019 23:06:32 GMT</pubDate>
    <dc:creator>panguy</dc:creator>
    <dc:date>2019-06-25T23:06:32Z</dc:date>
    <item>
      <title>Palo Alto Traps - No Wildfire data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Traps-No-Wildfire-data/m-p/419719#M51169</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;
Splunk is receiving data from Palo Alto Traps (via TCP in a dedicated index). Endpoint Operations dashboard is showing data.&lt;BR /&gt;
Admins of Traps are expecting to see also data for wildfire, like&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;Jun 11 2019 14:26:23 172.16.71.122 CEF:0|Palo Alto Networks|Traps Agent|4.2.3.41131|Notification Event|Threat|6|rt=Jun 11 2019 14:26:23 dhost=*** duser=*** cs2Label=Module cs2=WildFire deviceProcessName=*** fileHash=*** cs3Label=ContentVersion cs3=*** dvc=*** cs5Label=EventTime cs5=Jun 11 2019 14:26:14 msg=New notification event. Prevention Key: ***&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I checked the troubleshooting guide. Typically, I don't get any result for &lt;BR /&gt;
&lt;CODE&gt;eventtype=pan_wildfire&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I checked some of the props/transform regex, and none seems to identify those lines as wildfire events. Seems then correct that nothing pops up in the dashboard.&lt;BR /&gt;
What raw data should I expect to find in my index confirming that I get wildfire events.&lt;/P&gt;

&lt;P&gt;Thanks in advance for your help&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 07:57:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Traps-No-Wildfire-data/m-p/419719#M51169</guid>
      <dc:creator>dalambiel</dc:creator>
      <dc:date>2019-06-12T07:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Traps - No Wildfire data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Traps-No-Wildfire-data/m-p/419720#M51170</link>
      <description>&lt;P&gt;The pan_wildfire event type comes from Palo Alto Networks Firewall logs. Typically it is a THREAT log type with a subtype of wildfire. The wildfire dashboard will get populated when Firewall logs are being sent to Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 23:06:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Traps-No-Wildfire-data/m-p/419720#M51170</guid>
      <dc:creator>panguy</dc:creator>
      <dc:date>2019-06-25T23:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Traps - No Wildfire data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Traps-No-Wildfire-data/m-p/419721#M51171</link>
      <description>&lt;P&gt;Thanks for your response. &lt;BR /&gt;
That's explain it: we have only Traps, not the Palo Alto Firewall. Then no data for the dashboard using the pan_wildfire eventtype.&lt;/P&gt;

&lt;P&gt;Sorry for the late response: i was out of office for a few days.&lt;BR /&gt;
Thanks again.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 12:26:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Traps-No-Wildfire-data/m-p/419721#M51171</guid>
      <dc:creator>dalambiel</dc:creator>
      <dc:date>2019-07-03T12:26:54Z</dc:date>
    </item>
  </channel>
</rss>

