Hi,
We have recently set up Credential Phishing Prevention and would like to alert in splunk when the Credential Detected is yes.
Is this currently possible?
The flag doesn't appear to be sent with the syslog to Splunk.
Cheers,
Mat
Hello, the credential detected field will be parsed in the next version of the Palo Alto Networks Add-on (version 6.1.0). In the meantime, you can use the workaround in this feature request to add the feature to your current version of the Add-on:
https://github.com/PaloAltoNetworks/Splunk_TA_paloalto/issues/28
Hello, the credential detected field will be parsed in the next version of the Palo Alto Networks Add-on (version 6.1.0). In the meantime, you can use the workaround in this feature request to add the feature to your current version of the Add-on:
https://github.com/PaloAltoNetworks/Splunk_TA_paloalto/issues/28