All Apps and Add-ons

Palo Alto Logs Duplicated

mpower_interac
Explorer

Our PAN firewalls log to Splunk via Syslog, when reading the the log entries in Splunk the entry is duplicated (on the same line, the log shows up twice. Can anyone help me figure out what is causing this? We have the latest version of the Palo Alto Networks Add-on for Splunk installed.
https://splunkbase.splunk.com/app/2757/

0 Karma

panguy
Contributor

Are you seeing 2 entries in splunk that are the same or 1 entry in splunk with 2 lines of the same log?

0 Karma

mpower_interac
Explorer

1 entry in Splunk with 2 lines of the same log

0 Karma

panguy
Contributor

This might be an issue with your syslog-ng server. I would recommend checking the config on the syslog server. Did you follow this guide: https://splunk.paloaltonetworks.com/universal-forwarder.html?

0 Karma

mpower_interac
Explorer

Unfortunately we use rsyslog and I'm not an expert - I can get some help internally to figure out if the config is good but does PAN have any documentation for rsyslog instead of syslog-ng? I don't see anything on that page.

0 Karma

panguy
Contributor

Unfortunately, we don't have documentation on rsyslog. Essentially you want to make sure rsyslog does not do any type of parsing before it forwards to Splunk. You will need to check documentation on how to do this with rsyslog.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...