All Apps and Add-ons

Palo Alto Networks Add-on: Can we receive TCP data on Port 80 from Panorama?

phularah
Communicator

I want my Splunk Heavy Forwarder to receive TCP data on port 80 using Panorama. I have installed Palo Alto Networks add-on for Splunk on said Heavy Forwarder. Am I required to make any specific configurations in the add-on? I am not interested in using Wildfire, Aperture etc. I am only interested in getting firewall data in my Splunk indexer. Firewalls are already configured to store data in Panorama. Total no. of firewalls is 6 in number.

I have created a TCP data input in my heavy forwarder for that. I have also asked the security team to create a profile for Http(s) server (which will be Splunk) on Panorama.

Do I need to follow any more steps? Any ideas or suggestions? @btorresgil, @adonio, @panguy

0 Karma
1 Solution

phularah
Communicator

I integrated Palo Alto with Splunk a few days back. I used port 514 instead. I made a data input in Splunk on port 514 and asked Security team to send data from Panorama to the data input. Everything works fine.

View solution in original post

0 Karma

phularah
Communicator

I integrated Palo Alto with Splunk a few days back. I used port 514 instead. I made a data input in Splunk on port 514 and asked Security team to send data from Panorama to the data input. Everything works fine.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...