All Apps and Add-ons

Palo Alto app is not transoforming sourcetypes on splunk cloud

jared_anderson
Path Finder

We are sending palo alto logs over UDP to a heavy fowarwarder which is forwarding logs to splunk cloud. The palo alto TA is not transforming the sourcetype correctly. In the indexed data the sourcetype is pan:log rather than pan:threat, pan:traffic etc. This is working fine in our on-prem environment.

The following is the stanza with our palo alto config.

[udp://50534]
connection_host = ip
sourcetype = pan:log
source = udp:50534
index = paloalto
disabled = 0

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...