All Apps and Add-ons

Palo Alto app is not transoforming sourcetypes on splunk cloud

jared_anderson
Path Finder

We are sending palo alto logs over UDP to a heavy fowarwarder which is forwarding logs to splunk cloud. The palo alto TA is not transforming the sourcetype correctly. In the indexed data the sourcetype is pan:log rather than pan:threat, pan:traffic etc. This is working fine in our on-prem environment.

The following is the stanza with our palo alto config.

[udp://50534]
connection_host = ip
sourcetype = pan:log
source = udp:50534
index = paloalto
disabled = 0

0 Karma
Get Updates on the Splunk Community!

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering.  Because we’ve ...

How to Send Splunk Observability Alerts to Webex teams in Minutes

As a Developer Evangelist at Splunk, my team and I are constantly tinkering with technology to explore its ...