All Apps and Add-ons
Highlighted

Palo Alto Networks Add-on for Splunk: Why is the pan_endpoint stanza missing in tags.conf?

Splunk Employee
Splunk Employee

In the Palo Alto Networks Add-on for Splunk (SplunkTApaloalto) version 3.7.1, the panendpoint stanza is missing tags in the event types.conf file, and the panendpoint stanza is missing altogether in the tags.conf file. Why?

0 Karma
Highlighted

Re: Palo Alto Networks Add-on for Splunk: Why is the pan_endpoint stanza missing in tags.conf?

Splunk Employee
Splunk Employee

This isn't an answer to the question, but is how I dealt with the issue: I added the [panendpoint] stanza to the bottom of the tags.conf file in the local directory; I added 3 tags (malware, attack and operations) and I then disabled them. I did this as I had no data to drive the associated panendpoint search.

View solution in original post

0 Karma