All Apps and Add-ons

Guieds

hazem
Path Finder

Is there any guide on how to configure security products to send their logs to Splunk or what are the recommended logs that should be sent, like the DSM guide in QRadar?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @hazem ,

for many products there are some guides for integration with Splunk developed by the same third party vendor and the only way is to search on Google (e.g for Sophos you can see at https://partnernews.sophos.com/it-it/2021/05/prodotti/splunk-integration-for-sophos-firewall/).

Anyway, searching "Splunk Getting data in"  you have a guide to Datas ingestion in Splunk: https://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor  .

At least, the first approach to data ingestion should be identify the technology to ingest and searching the related Add-On in apps.splunk.com, that usually guides users to integration.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hazem ,

for many products there are some guides for integration with Splunk developed by the same third party vendor and the only way is to search on Google (e.g for Sophos you can see at https://partnernews.sophos.com/it-it/2021/05/prodotti/splunk-integration-for-sophos-firewall/).

Anyway, searching "Splunk Getting data in"  you have a guide to Datas ingestion in Splunk: https://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor  .

At least, the first approach to data ingestion should be identify the technology to ingest and searching the related Add-On in apps.splunk.com, that usually guides users to integration.

Ciao.

Giuseppe

0 Karma

hazem
Path Finder

Thank you @gcusello for your reply.

Our customer has asked me about the recommended log level that should be sent, for example, from Palo Alto to Splunk. Do you have any answer for this?"

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hazem ,

it depends on your Use cases: what do you want to monitor?

use a log level that gives you the data you need, I cannot say to you from outside what's the best log level.

In general, except some situations, I'd avoid the debug level and I'd use Alert level, but, as I said, it depends on your Use Cases.

In addition, this is a question for Palo Alto experts not Splunk because they know the contents of each log level.

Ciao.

Giuseppe

0 Karma

hazem
Path Finder

Hi @gcusello 

many thanks ,appreciate your support

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hazem ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...