All Apps and Add-ons

No Palo Alto Wildfire report data in Splunk Cloud

awesomeguan
New Member

Hi,
After following steps in WildFire in below url https://splunk.paloaltonetworks.com/wildfire.html
Add the Wildfire API key
There is no data seen in Splunk Cloud.
Please help to check Wildfire side to see if there any error message when Splunk Cloud tried to talk to it.

By the way, we also send the Panorama logs via on-premise Splunk heavy forwarder to Splunk Cloud and it's working as designed.

Thank you.

0 Karma

awesomeguan
New Member

Answers from Palo Alto support:

Regarding Splunk-Palo Alto networks App, kindly be advised that this is a developer supported application so it is not supported by through this channel TAC

In order to receive support for your Splunk app

https://splunk.paloaltonetworks.com/support.html
(reference https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CllZCAS)

Anyway for courtesy checking, the WildFire API key on our Splunk App will not be used unless there are WildFire logs coming from the Firewall or Panorama (it is just used for enriching the raw log with WildFIre analysis report from the cloud as per documentation).

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...