<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo Alto new log category help in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Palo-Alto-new-log-category-help/m-p/565157#M100580</link>
    <description>&lt;P class="p1"&gt;&lt;SPAN&gt;I have no idea what I need to do here (if anything), and the guy who has dealt with getting data in previously is on holiday for a while so any advice is much appreciated&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s2"&gt;We upgraded our Palo Alto firewall to a newer version which has moved the VPN logs from the system category to a separate one for GlobalProtect (more info &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/globalprotect-features/enhanced-logging-for-globalprotect" target="_blank" rel="noopener"&gt;&lt;SPAN class="s3"&gt;here&lt;/SPAN&gt;&lt;/A&gt; ) &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s2"&gt;When I noticed we weren’t receiving the VPN logs anymore, we got the firewall guys to forward the new log category to us and our Splunk guy assured me that we wouldn’t need to do anything else&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s2"&gt;However, the logs are supposedly being forwarded to us now but Splunk isn’t showing them, at least not in the index we have for the Palo Alto logs. Is our Splunk guy wrong and we do actually have to manually set up the new sourcetype? Or have the firewall guys messed up (harder to check due to language barriers and time differences)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s2"&gt;I am pretty clueless about this so apologies if this is a silly question&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 29 Aug 2021 00:06:52 GMT</pubDate>
    <dc:creator>LynneEss</dc:creator>
    <dc:date>2021-08-29T00:06:52Z</dc:date>
    <item>
      <title>Palo Alto new log category help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Palo-Alto-new-log-category-help/m-p/565157#M100580</link>
      <description>&lt;P class="p1"&gt;&lt;SPAN&gt;I have no idea what I need to do here (if anything), and the guy who has dealt with getting data in previously is on holiday for a while so any advice is much appreciated&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s2"&gt;We upgraded our Palo Alto firewall to a newer version which has moved the VPN logs from the system category to a separate one for GlobalProtect (more info &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/globalprotect-features/enhanced-logging-for-globalprotect" target="_blank" rel="noopener"&gt;&lt;SPAN class="s3"&gt;here&lt;/SPAN&gt;&lt;/A&gt; ) &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s2"&gt;When I noticed we weren’t receiving the VPN logs anymore, we got the firewall guys to forward the new log category to us and our Splunk guy assured me that we wouldn’t need to do anything else&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s2"&gt;However, the logs are supposedly being forwarded to us now but Splunk isn’t showing them, at least not in the index we have for the Palo Alto logs. Is our Splunk guy wrong and we do actually have to manually set up the new sourcetype? Or have the firewall guys messed up (harder to check due to language barriers and time differences)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s2"&gt;I am pretty clueless about this so apologies if this is a silly question&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Aug 2021 00:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Palo-Alto-new-log-category-help/m-p/565157#M100580</guid>
      <dc:creator>LynneEss</dc:creator>
      <dc:date>2021-08-29T00:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto new log category help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Palo-Alto-new-log-category-help/m-p/565160#M100581</link>
      <description>&lt;P&gt;It's not clear how you're receiving the logs and what's your configuration. &lt;EM&gt;Unless you're actively filtering the event categories&lt;/EM&gt; the data should land somewhere if it is within the same syslog stream as the events you can see.&lt;/P&gt;&lt;P&gt;Did you confirm (tcpdump? some debug on your syslog layer if you use some intermediate solution) that the events are really getting sent?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Aug 2021 06:39:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Palo-Alto-new-log-category-help/m-p/565160#M100581</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-08-29T06:39:54Z</dc:date>
    </item>
  </channel>
</rss>

