All Apps and Add-ons

CIM datamodel mapping for PaloAlto threat (including URL Filtering) log

HiroshiSatoh
Champion

I would like to borrow the wisdom of the Palo Alto experienced person.
Which data model does PaloAlto's threat (including URL Filtering) correspond to? "Intrusion Detection"?

0 Karma
1 Solution

lakshman239
Influencer

The PA firewall supports a number of Datamodels - Network Traffic, Network Sessions, Malware, Web .

If you install the Splunk Add on for Palo Alto and look at the default/tags.conf and eventtypes.conf, you can see all the event grouping and tags corresponding to the datamodel.

The events - threat/traffic all depends on the license for the modules which you may have on the PA.

View solution in original post

DEAD_BEEF
Builder

Documentation from Palo now breaks out each sourcetype into it's intended CIM datamodel.

lakshman239
Influencer

The PA firewall supports a number of Datamodels - Network Traffic, Network Sessions, Malware, Web .

If you install the Splunk Add on for Palo Alto and look at the default/tags.conf and eventtypes.conf, you can see all the event grouping and tags corresponding to the datamodel.

The events - threat/traffic all depends on the license for the modules which you may have on the PA.

Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...