<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Generating alerts using Palo Alto in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702357#M20571</link>
    <description>&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;I will choose the Splunk-supported add-on.&lt;/P&gt;</description>
    <pubDate>Mon, 21 Oct 2024 08:03:30 GMT</pubDate>
    <dc:creator>m_tanaka</dc:creator>
    <dc:date>2024-10-21T08:03:30Z</dc:date>
    <item>
      <title>Generating alerts using Palo Alto</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702016#M20515</link>
      <description>&lt;P&gt;I am from Japan. Sorry for my poor English and lack of knowledge about Splunk.&lt;/P&gt;&lt;P&gt;I received a Splunk Enterprise Trial License and would like to import Palo Alto logs and issue alerts (via email, etc.), but I am not sure how to do this (manually importing past logs succeeded). I wonder if past logs can issue alert.&lt;/P&gt;&lt;P&gt;About our environment, I set up all-in-one virtual server in our FJ Cloud (Fujitsu Cloud)is one virtual server and Splunk is running here. There are no forwarders installed on other servers.&lt;/P&gt;&lt;P&gt;I would be more than happy if you could let me know. Thank you for your support.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 01:58:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702016#M20515</guid>
      <dc:creator>m_tanaka</dc:creator>
      <dc:date>2024-10-16T01:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Generating alerts using Palo Alto</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702188#M20547</link>
      <description>&lt;P&gt;Palo introduced HTTP Event stream in OS 8.x, so if you have anything recent install it should support that as outbound log streaming.&amp;nbsp; Alternatively the logs can be exported over syslog but becomes infinitely more difficult ingest if you have a novice Splunk experience.&lt;/P&gt;&lt;P&gt;Once you can export from Palo the HTTP Event stream then you need to setup your Splunk instance to collect HEC/HTTP Event Collection and there is a lot of documentation on how to do that.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Warning&lt;/STRONG&gt;&lt;/U&gt;: Palo can generate a tremendous amount of logs and almost certainly exceeds your trial license capacity.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 14:57:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702188#M20547</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-10-17T14:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Generating alerts using Palo Alto</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702249#M20553</link>
      <description>&lt;P&gt;Thank you for your reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our department's policy seems to be to use exporting syslog and forwarding...&lt;/P&gt;&lt;P&gt;I referred to this video&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=wS5-jMS080s" target="_blank"&gt;https://www.youtube.com/watch?v=wS5-jMS080s&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and I'm trying to monitor syslog over Splunk. However no events displayed on Splunk search.&lt;/P&gt;&lt;P&gt;I used Wireshark (tshark), and then confirmed that Splunk server could receive syslog packets.&lt;/P&gt;&lt;P&gt;Is there anything else that I should check ?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 08:30:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702249#M20553</guid>
      <dc:creator>m_tanaka</dc:creator>
      <dc:date>2024-10-18T08:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Generating alerts using Palo Alto</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702283#M20557</link>
      <description>&lt;P&gt;There is an add-on for Palo Alto solutions.&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/7523" target="_blank"&gt;https://splunkbase.splunk.com/app/7523&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It is Splunk-supported so it should have a pretty decent manual.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 20:31:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702283#M20557</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-10-18T20:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Generating alerts using Palo Alto</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702335#M20563</link>
      <description>&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;There are two add-ons "&lt;SPAN&gt;Palo Alto Networks Add-on&lt;/SPAN&gt;" and "&lt;SPAN&gt;Splunk Add-on for Palo Alto Networks&lt;/SPAN&gt;".&lt;/P&gt;&lt;P&gt;Is there okay to go with either one ?&lt;/P&gt;&lt;P&gt;The video I referred on Youtube was about "&lt;SPAN&gt;Palo Alto Networks Add-on", and search result was displayed successfully.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I confirmed that the splunk server could received the syslog packets successfully using tshark.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;what is the problem in displaying the search results.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 00:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702335#M20563</guid>
      <dc:creator>m_tanaka</dc:creator>
      <dc:date>2024-10-21T00:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Generating alerts using Palo Alto</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702336#M20564</link>
      <description>&lt;P&gt;The palo alto server transmit the syslog with the port 5514. (514 port was in use)&lt;/P&gt;&lt;P&gt;And I search with the query "source="udp:5514"".&lt;/P&gt;&lt;P&gt;Is there any problem in the query ?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 01:25:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702336#M20564</guid>
      <dc:creator>m_tanaka</dc:creator>
      <dc:date>2024-10-21T01:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Generating alerts using Palo Alto</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702350#M20569</link>
      <description>&lt;P&gt;No. One is written by Palo Alto themselves - &lt;A href="https://splunkbase.splunk.com/app/2757" target="_blank"&gt;https://splunkbase.splunk.com/app/2757&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It's the older one and it's now deprecated.&lt;/P&gt;&lt;P&gt;The new one is written and supported by Splunk - &lt;A href="https://splunkbase.splunk.com/app/7523" target="_blank"&gt;https://splunkbase.splunk.com/app/7523&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Go for this one.&lt;/P&gt;&lt;P&gt;As a rule of thumb if you have a choice between a Splunk-supported add-on and a third-party one use the Splunk-supported one.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 06:23:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702350#M20569</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-10-21T06:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: Generating alerts using Palo Alto</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702357#M20571</link>
      <description>&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;I will choose the Splunk-supported add-on.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 08:03:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702357#M20571</guid>
      <dc:creator>m_tanaka</dc:creator>
      <dc:date>2024-10-21T08:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Generating alerts using Palo Alto</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702360#M20572</link>
      <description>&lt;P&gt;The upside to the Splunk-supported add-ons is that they have decent documentation. In this case it's&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.github.io/splunk-add-on-for-palo-alto-networks/" target="_blank"&gt;https://splunk.github.io/splunk-add-on-for-palo-alto-networks/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 09:10:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702360#M20572</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-10-21T09:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Generating alerts using Palo Alto</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702361#M20573</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;I will use it as a reference.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 09:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702361#M20573</guid>
      <dc:creator>m_tanaka</dc:creator>
      <dc:date>2024-10-21T09:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Generating alerts using Palo Alto</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702381#M20576</link>
      <description>&lt;P&gt;What is your Splunk configuration to listen for UDP 5514?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 14:48:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702381#M20576</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-10-21T14:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Generating alerts using Palo Alto</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702456#M20581</link>
      <description>&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;UDP 514 port was in use. I have&amp;nbsp; no idea why it is used by another process. So, I needed to use another port to receive packets from palo alto server.&lt;/P&gt;&lt;P&gt;However I solved this problem. The firewalld daemon was blocking the packets coming in Splunk. I stopped the firewalld, and could search the palo alto logs.&lt;/P&gt;&lt;P&gt;I go for the next step of issuing alerts from these logs.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 00:30:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Generating-alerts-using-Palo-Alto/m-p/702456#M20581</guid>
      <dc:creator>m_tanaka</dc:creator>
      <dc:date>2024-10-22T00:30:34Z</dc:date>
    </item>
  </channel>
</rss>

