All Apps and Add-ons

Palo Alto Networks Add-on: Can we receive TCP data on Port 80 from Panorama?

phularah
Communicator

I want my Splunk Heavy Forwarder to receive TCP data on port 80 using Panorama. I have installed Palo Alto Networks add-on for Splunk on said Heavy Forwarder. Am I required to make any specific configurations in the add-on? I am not interested in using Wildfire, Aperture etc. I am only interested in getting firewall data in my Splunk indexer. Firewalls are already configured to store data in Panorama. Total no. of firewalls is 6 in number.

I have created a TCP data input in my heavy forwarder for that. I have also asked the security team to create a profile for Http(s) server (which will be Splunk) on Panorama.

Do I need to follow any more steps? Any ideas or suggestions? @btorresgil, @adonio, @panguy

0 Karma
1 Solution

phularah
Communicator

I integrated Palo Alto with Splunk a few days back. I used port 514 instead. I made a data input in Splunk on port 514 and asked Security team to send data from Panorama to the data input. Everything works fine.

View solution in original post

0 Karma

phularah
Communicator

I integrated Palo Alto with Splunk a few days back. I used port 514 instead. I made a data input in Splunk on port 514 and asked Security team to send data from Panorama to the data input. Everything works fine.

0 Karma
Get Updates on the Splunk Community!

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...

Stay Connected: Your Guide to October Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...