All Apps and Add-ons

CIM datamodel mapping for PaloAlto threat (including URL Filtering) log

HiroshiSatoh
Champion

I would like to borrow the wisdom of the Palo Alto experienced person.
Which data model does PaloAlto's threat (including URL Filtering) correspond to? "Intrusion Detection"?

0 Karma
1 Solution

lakshman239
SplunkTrust
SplunkTrust

The PA firewall supports a number of Datamodels - Network Traffic, Network Sessions, Malware, Web .

If you install the Splunk Add on for Palo Alto and look at the default/tags.conf and eventtypes.conf, you can see all the event grouping and tags corresponding to the datamodel.

The events - threat/traffic all depends on the license for the modules which you may have on the PA.

View solution in original post

DEAD_BEEF
Builder

Documentation from Palo now breaks out each sourcetype into it's intended CIM datamodel.

lakshman239
SplunkTrust
SplunkTrust

The PA firewall supports a number of Datamodels - Network Traffic, Network Sessions, Malware, Web .

If you install the Splunk Add on for Palo Alto and look at the default/tags.conf and eventtypes.conf, you can see all the event grouping and tags corresponding to the datamodel.

The events - threat/traffic all depends on the license for the modules which you may have on the PA.

Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...