<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prisma Cloud integration in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Prisma-Cloud-integration/m-p/504672#M1992</link>
    <description>&lt;P&gt;Has anyone integrated Prisma Cloud into Splunk Enterprise on AWS (either via SQS or API Gateway + Lambda + HEC) to &lt;SPAN class="ph cmd"&gt;view alert notifications from Prisma Cloud in Splunk&lt;/SPAN&gt;?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-amazon-sqs.html" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-amazon-sqs.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-splunk" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-splunk&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jun 2020 18:54:08 GMT</pubDate>
    <dc:creator>SimonO</dc:creator>
    <dc:date>2020-06-16T18:54:08Z</dc:date>
    <item>
      <title>Prisma Cloud integration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Prisma-Cloud-integration/m-p/504672#M1992</link>
      <description>&lt;P&gt;Has anyone integrated Prisma Cloud into Splunk Enterprise on AWS (either via SQS or API Gateway + Lambda + HEC) to &lt;SPAN class="ph cmd"&gt;view alert notifications from Prisma Cloud in Splunk&lt;/SPAN&gt;?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-amazon-sqs.html" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-amazon-sqs.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-splunk" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-splunk&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 18:54:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Prisma-Cloud-integration/m-p/504672#M1992</guid>
      <dc:creator>SimonO</dc:creator>
      <dc:date>2020-06-16T18:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Cloud integration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Prisma-Cloud-integration/m-p/504678#M1993</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222567"&gt;@SimonO&lt;/a&gt;&lt;BR /&gt;Yes.I've used Splunk HEC token and configured it on Prisma to capture prisma alerts data to Splunk. If you want to go with HEC then use Splunk Integration option on Prisma .&lt;/P&gt;&lt;P&gt;But my recommendation would be, as the data is coming from cloud to on premesis you can place proper SSL cerificates to get this done work properly. I'd place certificate for HEC like this&lt;BR /&gt;&lt;BR /&gt;splunk_httpinput/local/inputs.conf&lt;BR /&gt;[http]&lt;BR /&gt;disabled = 0&lt;BR /&gt;enableSSL = 1&lt;BR /&gt;serverCert = /opt/splunk/etc/auth/certs/prisma-cert.pem&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 19:24:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Prisma-Cloud-integration/m-p/504678#M1993</guid>
      <dc:creator>muralikoppula</dc:creator>
      <dc:date>2020-06-16T19:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Cloud integration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Prisma-Cloud-integration/m-p/522442#M3642</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/112484"&gt;@muralikoppula&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, I have also tried using the HEC, but is gives me error "SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client key exchange A', alert_description='certificate unknown'.&lt;BR /&gt;10-01-2020 00:05:38.336 +0100 WARN HttpListener - Socket error from XX.XX.XX.XX:11651 while idling: error:14094416:SSL routines:ssl3_read_bytes:sslv3 alert certificate unknown".&lt;/P&gt;&lt;P&gt;Although same certificate is working fine for Splunk Web.&lt;/P&gt;&lt;P&gt;Any help will be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 09:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Prisma-Cloud-integration/m-p/522442#M3642</guid>
      <dc:creator>Priyankakumari1</dc:creator>
      <dc:date>2020-10-01T09:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Cloud integration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Prisma-Cloud-integration/m-p/560487#M6488</link>
      <description>&lt;P&gt;does the HEC url have to be hosted on Splunk cloud infrastructure to be accessible by Cloud Prisma ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 14:52:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Prisma-Cloud-integration/m-p/560487#M6488</guid>
      <dc:creator>sbsplunkuser</dc:creator>
      <dc:date>2021-07-22T14:52:26Z</dc:date>
    </item>
  </channel>
</rss>

