All Apps and Add-ons

Palo Alto Networks - threats and webfiltering

mjcocat
New Member

I followed the instructions for setting up the Palo Alto app, and things seem to be working OK with the exception of certain logs. I have nothing showing up for threats and/or web filtering. I know for a fact that the rule I am logging has blocked certain websites.

0 Karma

darlas
Communicator

I have a similar issue but with the Content and Wildfire dashboards not showing any data. I have data on the Overview, Traffic and Threat dashboards.

Any ideas?

0 Karma

mjcocat
New Member

The problem was that I didn't enable the threat logs on the PA, just traffic logs. Thanks for the follow up!

0 Karma

monzy
Communicator

can you find the threat log or the web traffic log when you do search ? e.g. what do you get results when you run the following search in the search bar
index=pan_logs threat | head 100

if you don't get any results then a change has to be made on the firewall side to send the appropriate logs. if you do get results and you are not seeing anything in a dashboard, then please share a couple of log lines so we can confirm that they match what the app expects.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...