<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs from PaloAlto in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684879#M114274</link>
    <description>&lt;P&gt;I tried to query "&lt;/P&gt;&lt;PRE&gt;index=_internal source=*metrics.log group=udpin_connections 192.168.3.5&lt;/PRE&gt;&lt;P&gt;It did not come back with anything.&lt;/P&gt;&lt;P&gt;I believe&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Data Input.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30505iCB23530F0B21FEA1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Data Input.jpg" alt="Data Input.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk Index Detail.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30506iD44B744A22DC84E1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk Index Detail.jpg" alt="Splunk Index Detail.jpg" /&gt;&lt;/span&gt; i have configured the data input correctly and pointing to right index&lt;/P&gt;</description>
    <pubDate>Sat, 20 Apr 2024 19:27:42 GMT</pubDate>
    <dc:creator>Rabab</dc:creator>
    <dc:date>2024-04-20T19:27:42Z</dc:date>
    <item>
      <title>Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684832#M114261</link>
      <description>&lt;P&gt;I have Splunk Installed on a windows machine and configured PaloAlto app along with Add on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have done configurations on Palo Alto. I can see from packet Capture that palo alto is sending logs successfully to the windows machine where splunk is installed but I cannot see anything in splunk itself. Can anyone help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Rabab&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 22:10:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684832#M114261</guid>
      <dc:creator>Rabab</dc:creator>
      <dc:date>2024-04-19T22:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684833#M114262</link>
      <description>&lt;P&gt;Hi Rabab,&lt;BR /&gt;&lt;BR /&gt;A few more details will be needed to help here.&lt;BR /&gt;&lt;BR /&gt;Is your Palo Alto setup sending directly to Splunk, with a syslog server, or&amp;nbsp; via an HF/UF?&lt;BR /&gt;&lt;BR /&gt;Where have you tried looking for the data? Have you looked to see if any of your indexes are growing?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 23:13:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684833#M114262</guid>
      <dc:creator>P_vandereerden</dc:creator>
      <dc:date>2024-04-19T23:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684836#M114264</link>
      <description>&lt;P&gt;Hello Paul,&lt;/P&gt;&lt;P&gt;Thank you for a quick response, Its direct from Palo to to Splunk. I am using Paloalto App and Add on,&amp;nbsp; I am not seeing indexes growing at all. I tried looking at the data from Search option and try to match with various filters.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Rabab&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 00:36:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684836#M114264</guid>
      <dc:creator>Rabab</dc:creator>
      <dc:date>2024-04-20T00:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684850#M114265</link>
      <description>&lt;P&gt;I assume PAlto is sending events as syslog data. As you're using Windows I suspect you're not using any additional syslog receiver but want to receive syslog directly on your Splunk (which is not the best idea but let's leave it for now). Have you configured any inputs on your Splunk instance to receive the syslog events? Do you have proper rules in your server's firewall to allow for this traffic?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 06:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684850#M114265</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-20T06:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684861#M114268</link>
      <description>&lt;P&gt;Hello PickleRick,&lt;/P&gt;&lt;P&gt;I he created data input o allow udp14 traffic. So is index. Please check these screenshots for clarity,&amp;nbsp;&lt;/P&gt;&lt;P&gt;192.168.3.5 is Palo Device and 192.168.3.1 is windows machine where &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Palo Syslog capture.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30503i8791551EE23D5EBD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Palo Syslog capture.jpg" alt="Palo Syslog capture.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk Index.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30501i372A281B692753E6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk Index.jpg" alt="Splunk Index.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk Input.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30502i7ECACB567179BA71/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk Input.jpg" alt="Splunk Input.jpg" /&gt;&lt;/span&gt;Splunk is installed&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 11:01:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684861#M114268</guid>
      <dc:creator>Rabab</dc:creator>
      <dc:date>2024-04-20T11:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684876#M114273</link>
      <description>&lt;P&gt;That dump looks pretty much OK.&lt;/P&gt;&lt;P&gt;Are you 100% sure your udp:514 input sends to the right index? You can also try to find reports about that particular source of syslog data with&lt;/P&gt;&lt;PRE&gt;index=_internal source=*metrics.log group=udpin_connections 192.168.3.5&lt;/PRE&gt;&lt;P&gt;If Splunk is receiving data from this host on that udp input, you should get some results with metrics field like _udp_bps,&amp;nbsp; _udp_eps and so on.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 18:22:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684876#M114273</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-20T18:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684879#M114274</link>
      <description>&lt;P&gt;I tried to query "&lt;/P&gt;&lt;PRE&gt;index=_internal source=*metrics.log group=udpin_connections 192.168.3.5&lt;/PRE&gt;&lt;P&gt;It did not come back with anything.&lt;/P&gt;&lt;P&gt;I believe&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Data Input.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30505iCB23530F0B21FEA1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Data Input.jpg" alt="Data Input.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk Index Detail.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30506iD44B744A22DC84E1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk Index Detail.jpg" alt="Splunk Index Detail.jpg" /&gt;&lt;/span&gt; i have configured the data input correctly and pointing to right index&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 19:27:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684879#M114274</guid>
      <dc:creator>Rabab</dc:creator>
      <dc:date>2024-04-20T19:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684881#M114275</link>
      <description>&lt;P&gt;At first glance looks pretty OK.&lt;/P&gt;&lt;P&gt;Check your windows firewall.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 20:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684881#M114275</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-20T20:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684882#M114276</link>
      <description>&lt;P&gt;For testing, I have disabled the windows firewall. But I can see that logs are actually arriving within the windows machine and Splunk is not picking them up.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 20:08:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684882#M114276</guid>
      <dc:creator>Rabab</dc:creator>
      <dc:date>2024-04-20T20:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684883#M114277</link>
      <description>&lt;P&gt;Well, there are no miracles. I understand that the packets show up on the interface but apparently are not picked up by Splunk. Question is whether it listens on the port at all (even though the input is defined, something might be preventing Splunk from binding to the port).&lt;/P&gt;&lt;P&gt;Did you verify with netstat that the Splunk process is actually listening on this port?&lt;/P&gt;&lt;P&gt;(BTW, I don't remember if you don't need to restart splunkd after adding the input using WebUI or REST. You must do so if you change inputs by config files).&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 20:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684883#M114277</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-20T20:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684886#M114278</link>
      <description>&lt;P&gt;update: I have gone over the configs and&lt;/P&gt;&lt;P&gt;&amp;nbsp;index=_internal source=*metrics.log group=udpin_connections 192.168.3.5&lt;/P&gt;&lt;P&gt;is giving following output.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30507i28BF7F657F465176/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.jpg" alt="Untitled.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 22:58:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684886#M114278</guid>
      <dc:creator>Rabab</dc:creator>
      <dc:date>2024-04-20T22:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684894#M114279</link>
      <description>&lt;P&gt;We're getting somewhere &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As you can see some non-zero values, it means that some data is indeed being received by the udp input. Now we need to find where it goes to.&lt;/P&gt;&lt;P&gt;By the fact that it's a windows installation and because it's called "DESKTOP-something" I assume that it's your private test box and you're not having a lot of data on it. So you can run a&lt;/P&gt;&lt;PRE&gt;index=*&lt;/PRE&gt;&lt;P&gt;search over "All time (real-time)" - this is one of the very very rare cases where real-time search makes sanes. Very important - don't try this on any production or heavily loaded test box.&lt;/P&gt;&lt;P&gt;With this you can see the events as they come into your Splunk box (so if your events are rare you might to wait a while). Check the index, source, sourcetype and timestamp of the incoming events.&lt;/P&gt;&lt;P&gt;Another way to find where those events are could be to run&lt;/P&gt;&lt;PRE&gt;| tstats count where index=* by source sourcetype index&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2024 07:09:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684894#M114279</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-21T07:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684895#M114280</link>
      <description>&lt;P&gt;Its all working now, Thank you for your help&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2024 08:30:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684895#M114280</guid>
      <dc:creator>Rabab</dc:creator>
      <dc:date>2024-04-21T08:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from PaloAlto</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684896#M114281</link>
      <description>&lt;P&gt;For future reference so that if someone finds this thread has full information - tell us what did you do to make things work in the end/what was the problem.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2024 09:28:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-from-PaloAlto/m-p/684896#M114281</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-21T09:28:33Z</dc:date>
    </item>
  </channel>
</rss>

