<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic First Time Setup with Heavy Forwarder Help - Specific Palo Alto Question in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/First-Time-Setup-with-Heavy-Forwarder-Help-Specific-Palo-Alto/m-p/387853#M14094</link>
    <description>&lt;P&gt;I am setting up a new splunk environment and running into a few questions i am hoping i can get answers for.  My environment consists of three on prem enterprise instances.  A single search head, single indexer, and single heavy forwarder.  I am setting up the heavy forwarder as some of the splunk apps we want to use require it for "pre parsing".  With that in mind, i have the three instances configured and am ready to add my first data input.  I want to send my palo alto panorama logs to the heavy forwarder instance.&lt;/P&gt;

&lt;P&gt;I tried just setting up the syslog entry to port 514 and then create a syslog data input on the heavy forwarder to listen on that port.  But nothing is coming across.  In researching i think this is wrong, and what i need to do is:&lt;/P&gt;

&lt;P&gt;High level steps&lt;BR /&gt;
Install and configure a syslog-ng server&lt;BR /&gt;
Configure logging format for data to be received from the Palo Alto Networks appliance&lt;BR /&gt;
Configure Palo Alto Networks appliance logging, and output to the syslog-ng server&lt;BR /&gt;
Configure receiving of data on the Splunk platform indexer cluster&lt;BR /&gt;
Install a Splunk universal forwarder on the same host as the syslog-ng server&lt;BR /&gt;
Install the Splunk Add-on for Palo Alto Networks on the Splunk universal forwarder&lt;BR /&gt;
Install the Splunk Add-on for Palo Alto Networks across the Splunk platform deployment&lt;BR /&gt;
Configure the universal forwarder to monitor syslog-ng logs, and forward data to the Splunk platform&lt;BR /&gt;
Validate your data&lt;/P&gt;

&lt;P&gt;Can someone confirm this is the correct process?  If so i just need to go through and build a fourth linux box to act as the syslog-ng.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Nov 2018 13:42:57 GMT</pubDate>
    <dc:creator>ghostdog920</dc:creator>
    <dc:date>2018-11-19T13:42:57Z</dc:date>
    <item>
      <title>First Time Setup with Heavy Forwarder Help - Specific Palo Alto Question</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/First-Time-Setup-with-Heavy-Forwarder-Help-Specific-Palo-Alto/m-p/387853#M14094</link>
      <description>&lt;P&gt;I am setting up a new splunk environment and running into a few questions i am hoping i can get answers for.  My environment consists of three on prem enterprise instances.  A single search head, single indexer, and single heavy forwarder.  I am setting up the heavy forwarder as some of the splunk apps we want to use require it for "pre parsing".  With that in mind, i have the three instances configured and am ready to add my first data input.  I want to send my palo alto panorama logs to the heavy forwarder instance.&lt;/P&gt;

&lt;P&gt;I tried just setting up the syslog entry to port 514 and then create a syslog data input on the heavy forwarder to listen on that port.  But nothing is coming across.  In researching i think this is wrong, and what i need to do is:&lt;/P&gt;

&lt;P&gt;High level steps&lt;BR /&gt;
Install and configure a syslog-ng server&lt;BR /&gt;
Configure logging format for data to be received from the Palo Alto Networks appliance&lt;BR /&gt;
Configure Palo Alto Networks appliance logging, and output to the syslog-ng server&lt;BR /&gt;
Configure receiving of data on the Splunk platform indexer cluster&lt;BR /&gt;
Install a Splunk universal forwarder on the same host as the syslog-ng server&lt;BR /&gt;
Install the Splunk Add-on for Palo Alto Networks on the Splunk universal forwarder&lt;BR /&gt;
Install the Splunk Add-on for Palo Alto Networks across the Splunk platform deployment&lt;BR /&gt;
Configure the universal forwarder to monitor syslog-ng logs, and forward data to the Splunk platform&lt;BR /&gt;
Validate your data&lt;/P&gt;

&lt;P&gt;Can someone confirm this is the correct process?  If so i just need to go through and build a fourth linux box to act as the syslog-ng.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 13:42:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/First-Time-Setup-with-Heavy-Forwarder-Help-Specific-Palo-Alto/m-p/387853#M14094</guid>
      <dc:creator>ghostdog920</dc:creator>
      <dc:date>2018-11-19T13:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: First Time Setup with Heavy Forwarder Help - Specific Palo Alto Question</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/First-Time-Setup-with-Heavy-Forwarder-Help-Specific-Palo-Alto/m-p/387854#M14095</link>
      <description>&lt;P&gt;You checked you have set the input for 514 with udp:514 or tcp:514 so that it matches what the appliance is sending?&lt;BR /&gt;
Checked the index it's being sent to is correct and already exists?&lt;BR /&gt;
Setting up a syslog receiver to catch the events is a more robust solution as it does not stop/start with Splunk restarts.&lt;/P&gt;

&lt;P&gt;...Laurie:{)&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 21:36:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/First-Time-Setup-with-Heavy-Forwarder-Help-Specific-Palo-Alto/m-p/387854#M14095</guid>
      <dc:creator>laurie_gellatly</dc:creator>
      <dc:date>2018-11-19T21:36:20Z</dc:date>
    </item>
  </channel>
</rss>

