<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk and PA cortext data lake in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-and-Palo-Alto-Cortex-Data-Lake-Data-for-global-protect/m-p/547431#M65346</link>
    <description>&lt;P&gt;In case anyone else lands here, it appears Cortex Data Lake now supports forwarding directly to Splunk&amp;nbsp; via HTTP Event Collector (HEC).&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-log-forwarding-app/forward-logs-to-an-https-server" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-log-forwarding-app/forward-logs-to-an-https-server&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 11 Apr 2021 02:16:05 GMT</pubDate>
    <dc:creator>swebb07g</dc:creator>
    <dc:date>2021-04-11T02:16:05Z</dc:date>
    <item>
      <title>Splunk and Palo Alto Cortex Data Lake: Data for global protect cloud service is not getting parsed.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-and-Palo-Alto-Cortex-Data-Lake-Data-for-global-protect/m-p/493384#M60725</link>
      <description>&lt;P&gt;We are ingesting the firewall data from the panorama and GP cloud service logs from Cortex and ingesting the data to the same index pan_logs with sourcetype=pan:log.&lt;/P&gt;
&lt;P&gt;The logs from panorama are getting parsed properly, however, the data from the cortex data lake for global protect cloud service is not getting parsed. Does the Palo Alto Networks for Splunk add-on support data coming from Cortex? Any suggestions to make this work?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 22:31:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-and-Palo-Alto-Cortex-Data-Lake-Data-for-global-protect/m-p/493384#M60725</guid>
      <dc:creator>shirishkamat84</dc:creator>
      <dc:date>2020-08-20T22:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and PA cortext data lake</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-and-Palo-Alto-Cortex-Data-Lake-Data-for-global-protect/m-p/515318#M63095</link>
      <description>&lt;P&gt;I am trying to get data from cortex data lake to our Splunk hosted on prem. We getting the logs but it’s garbage characters.&lt;/P&gt;&lt;P&gt;splunk is not able to open ssl input. Can you share splunk side config to make this work?&lt;/P&gt;&lt;P&gt;what were the parameters on inputs.conf and what third party CA you user and created pem files?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any help would be appreciated&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 21:50:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-and-Palo-Alto-Cortex-Data-Lake-Data-for-global-protect/m-p/515318#M63095</guid>
      <dc:creator>hiren53</dc:creator>
      <dc:date>2020-08-20T21:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and Palo Alto Cortex Data Lake: Data for global protect cloud service is not getting parsed.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-and-Palo-Alto-Cortex-Data-Lake-Data-for-global-protect/m-p/534743#M64542</link>
      <description>&lt;P&gt;I'm also curious about this.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 23:57:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-and-Palo-Alto-Cortex-Data-Lake-Data-for-global-protect/m-p/534743#M64542</guid>
      <dc:creator>swebb07g</dc:creator>
      <dc:date>2021-01-04T23:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and PA cortext data lake</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-and-Palo-Alto-Cortex-Data-Lake-Data-for-global-protect/m-p/535412#M64601</link>
      <description>&lt;P&gt;I don't think Cortex Data Lake supports SSL (assuming you mean https). It does support syslog over TLS though.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 01:45:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-and-Palo-Alto-Cortex-Data-Lake-Data-for-global-protect/m-p/535412#M64601</guid>
      <dc:creator>swebb07g</dc:creator>
      <dc:date>2021-01-12T01:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and PA cortext data lake</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-and-Palo-Alto-Cortex-Data-Lake-Data-for-global-protect/m-p/547431#M65346</link>
      <description>&lt;P&gt;In case anyone else lands here, it appears Cortex Data Lake now supports forwarding directly to Splunk&amp;nbsp; via HTTP Event Collector (HEC).&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-log-forwarding-app/forward-logs-to-an-https-server" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-log-forwarding-app/forward-logs-to-an-https-server&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Apr 2021 02:16:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-and-Palo-Alto-Cortex-Data-Lake-Data-for-global-protect/m-p/547431#M65346</guid>
      <dc:creator>swebb07g</dc:creator>
      <dc:date>2021-04-11T02:16:05Z</dc:date>
    </item>
  </channel>
</rss>

