All Apps and Add-ons

Is Credential Detected send via syslog to Splunk?

mjohnstone75
New Member

Hi,

We have recently set up Credential Phishing Prevention and would like to alert in splunk when the Credential Detected is yes.

Is this currently possible?
The flag doesn't appear to be sent with the syslog to Splunk.

Cheers,
Mat

0 Karma
1 Solution

btorresgil
Builder

Hello, the credential detected field will be parsed in the next version of the Palo Alto Networks Add-on (version 6.1.0). In the meantime, you can use the workaround in this feature request to add the feature to your current version of the Add-on:
https://github.com/PaloAltoNetworks/Splunk_TA_paloalto/issues/28

View solution in original post

0 Karma

btorresgil
Builder

Hello, the credential detected field will be parsed in the next version of the Palo Alto Networks Add-on (version 6.1.0). In the meantime, you can use the workaround in this feature request to add the feature to your current version of the Add-on:
https://github.com/PaloAltoNetworks/Splunk_TA_paloalto/issues/28

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...