All Apps and Add-ons

How to have “Splunk for Palo Alto Networks” read from the default index?

jeffa
Path Finder

According to the setup documentation, the input for Splunk for Palo Alto Networks should write to the pan_logs index, however, I would prefer that it write to the default index. My hope is that making this change is as easy as updating the `pan_index` macro to point to the default index rather than pan_logs, but are there any other considerations?

0 Karma
1 Solution

jeffa
Path Finder

I did some experimentation with this and found that pointing the pan_index macro at the default index did allow me to view logs and dashboards from logs stored in the default index instead of the pan_logs index. However, the app author has stated that “Though keep in mind that this isn't really a supported configuration…” and that the configuration may cause issues w/ future releases.

The reason I originally asked the question is that up till now, I have used the index size limit of the default index to control disk utilization. Rather than putting the Palo Alto logs in the default index, the better answer was to implement “Volume settings” (indexes.conf) and place the default index, pan_logs index (and any other index that I want to control) into the same “volume”.

View solution in original post

0 Karma

jeffa
Path Finder

I did some experimentation with this and found that pointing the pan_index macro at the default index did allow me to view logs and dashboards from logs stored in the default index instead of the pan_logs index. However, the app author has stated that “Though keep in mind that this isn't really a supported configuration…” and that the configuration may cause issues w/ future releases.

The reason I originally asked the question is that up till now, I have used the index size limit of the default index to control disk utilization. Rather than putting the Palo Alto logs in the default index, the better answer was to implement “Volume settings” (indexes.conf) and place the default index, pan_logs index (and any other index that I want to control) into the same “volume”.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...