All Apps and Add-ons

Palo Alto Networks - threats and webfiltering

mjcocat
New Member

I followed the instructions for setting up the Palo Alto app, and things seem to be working OK with the exception of certain logs. I have nothing showing up for threats and/or web filtering. I know for a fact that the rule I am logging has blocked certain websites.

0 Karma

darlas
Communicator

I have a similar issue but with the Content and Wildfire dashboards not showing any data. I have data on the Overview, Traffic and Threat dashboards.

Any ideas?

0 Karma

mjcocat
New Member

The problem was that I didn't enable the threat logs on the PA, just traffic logs. Thanks for the follow up!

0 Karma

monzy
Communicator

can you find the threat log or the web traffic log when you do search ? e.g. what do you get results when you run the following search in the search bar
index=pan_logs threat | head 100

if you don't get any results then a change has to be made on the firewall side to send the appropriate logs. if you do get results and you are not seeing anything in a dashboard, then please share a couple of log lines so we can confirm that they match what the app expects.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...