<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get URL filtering logs from Palo Alto into Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-URL-filtering-logs-from-Palo-Alto-into-Splunk/m-p/162657#M33016</link>
    <description>&lt;P&gt;I don't use the profile Block List text box, so can't really answer for that specific use. Usually setting the action to block should send a syslog message&lt;/P&gt;

&lt;P&gt;If it doesn't log using the block list text box in the URL profile, you could try creating a custom category and add that to the URL profile.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Dec 2014 23:16:14 GMT</pubDate>
    <dc:creator>mbenwell</dc:creator>
    <dc:date>2014-12-22T23:16:14Z</dc:date>
    <item>
      <title>How to get URL filtering logs from Palo Alto into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-URL-filtering-logs-from-Palo-Alto-into-Splunk/m-p/162653#M33012</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I am trying to find out how to get URL filtering logs from a Palo Alto into Splunk.&lt;/P&gt;

&lt;P&gt;I do not see a URL filter log option in the "Log Forwarding Profile"&lt;/P&gt;

&lt;P&gt;I have the Palo Alto plug-in installed in Splunk.&lt;/P&gt;

&lt;P&gt;If it matters, I am using Splunk 6.1.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2014 20:27:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-URL-filtering-logs-from-Palo-Alto-into-Splunk/m-p/162653#M33012</guid>
      <dc:creator>craigmueller</dc:creator>
      <dc:date>2014-12-19T20:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to get URL filtering logs from Palo Alto into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-URL-filtering-logs-from-Palo-Alto-into-Splunk/m-p/162654#M33013</link>
      <description>&lt;P&gt;Hi @craigmueller&lt;/P&gt;

&lt;P&gt;By "Palo Alto plug-in", are you referring to the Splunk for Palo Alto Networks app (&lt;A href="https://apps.splunk.com/app/491/"&gt;https://apps.splunk.com/app/491/&lt;/A&gt; ) or the TA-paloalto for the Splunk App for Enterprise Security (&lt;A href="https://apps.splunk.com/app/263/"&gt;https://apps.splunk.com/app/263/&lt;/A&gt; )?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2014 20:42:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-URL-filtering-logs-from-Palo-Alto-into-Splunk/m-p/162654#M33013</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2014-12-19T20:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to get URL filtering logs from Palo Alto into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-URL-filtering-logs-from-Palo-Alto-into-Splunk/m-p/162655#M33014</link>
      <description>&lt;P&gt;You don't need to do anything special with the Palo Splunk App&lt;/P&gt;

&lt;P&gt;Assuming you have the appropriate security policy configured for url filtering, and that same policy is configured to forward syslog messages correctly. &lt;/P&gt;

&lt;P&gt;There are a couple of things to look at.  Most of the url logs are informational events. Check your syslog profile is set to send informational events.&lt;/P&gt;

&lt;P&gt;Also in the URL filtering configuration (Objects&amp;gt;security profiles&amp;gt;URL filtering). Set the desired categories to an action of 'alert' and it will syslog them out.  &lt;/P&gt;

&lt;P&gt;Then in splunk they will appear as a sourcetype of "pan_threat"&lt;/P&gt;

&lt;P&gt;There is also an option to 'log container page only' which will not log all content.  Uncheck that and you should get everything.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Dec 2014 02:33:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-URL-filtering-logs-from-Palo-Alto-into-Splunk/m-p/162655#M33014</guid>
      <dc:creator>mbenwell</dc:creator>
      <dc:date>2014-12-20T02:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to get URL filtering logs from Palo Alto into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-URL-filtering-logs-from-Palo-Alto-into-Splunk/m-p/162656#M33015</link>
      <description>&lt;P&gt;@mbenwell&lt;/P&gt;

&lt;P&gt;I know this is more of a PA question but, can you set up alerting for URLs on the URL Filtering Profile block list?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Dec 2014 16:59:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-URL-filtering-logs-from-Palo-Alto-into-Splunk/m-p/162656#M33015</guid>
      <dc:creator>craigmueller</dc:creator>
      <dc:date>2014-12-22T16:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to get URL filtering logs from Palo Alto into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-URL-filtering-logs-from-Palo-Alto-into-Splunk/m-p/162657#M33016</link>
      <description>&lt;P&gt;I don't use the profile Block List text box, so can't really answer for that specific use. Usually setting the action to block should send a syslog message&lt;/P&gt;

&lt;P&gt;If it doesn't log using the block list text box in the URL profile, you could try creating a custom category and add that to the URL profile.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Dec 2014 23:16:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-URL-filtering-logs-from-Palo-Alto-into-Splunk/m-p/162657#M33016</guid>
      <dc:creator>mbenwell</dc:creator>
      <dc:date>2014-12-22T23:16:14Z</dc:date>
    </item>
  </channel>
</rss>

