All Apps and Add-ons

CIM datamodel mapping for PaloAlto threat (including URL Filtering) log

HiroshiSatoh
Champion

I would like to borrow the wisdom of the Palo Alto experienced person.
Which data model does PaloAlto's threat (including URL Filtering) correspond to? "Intrusion Detection"?

0 Karma
1 Solution

lakshman239
Influencer

The PA firewall supports a number of Datamodels - Network Traffic, Network Sessions, Malware, Web .

If you install the Splunk Add on for Palo Alto and look at the default/tags.conf and eventtypes.conf, you can see all the event grouping and tags corresponding to the datamodel.

The events - threat/traffic all depends on the license for the modules which you may have on the PA.

View solution in original post

DEAD_BEEF
Builder

Documentation from Palo now breaks out each sourcetype into it's intended CIM datamodel.

lakshman239
Influencer

The PA firewall supports a number of Datamodels - Network Traffic, Network Sessions, Malware, Web .

If you install the Splunk Add on for Palo Alto and look at the default/tags.conf and eventtypes.conf, you can see all the event grouping and tags corresponding to the datamodel.

The events - threat/traffic all depends on the license for the modules which you may have on the PA.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...