All Apps and Add-ons

Palo Alto Logs Duplicated

mpower_interac
Explorer

Our PAN firewalls log to Splunk via Syslog, when reading the the log entries in Splunk the entry is duplicated (on the same line, the log shows up twice. Can anyone help me figure out what is causing this? We have the latest version of the Palo Alto Networks Add-on for Splunk installed.
https://splunkbase.splunk.com/app/2757/

0 Karma

panguy
Contributor

Are you seeing 2 entries in splunk that are the same or 1 entry in splunk with 2 lines of the same log?

0 Karma

mpower_interac
Explorer

1 entry in Splunk with 2 lines of the same log

0 Karma

panguy
Contributor

This might be an issue with your syslog-ng server. I would recommend checking the config on the syslog server. Did you follow this guide: https://splunk.paloaltonetworks.com/universal-forwarder.html?

0 Karma

mpower_interac
Explorer

Unfortunately we use rsyslog and I'm not an expert - I can get some help internally to figure out if the config is good but does PAN have any documentation for rsyslog instead of syslog-ng? I don't see anything on that page.

0 Karma

panguy
Contributor

Unfortunately, we don't have documentation on rsyslog. Essentially you want to make sure rsyslog does not do any type of parsing before it forwards to Splunk. You will need to check documentation on how to do this with rsyslog.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...