All Apps and Add-ons

Palo Alto logs + Syslog not showing up Palo Alto Add-On

tentontitan
New Member

I'm currently collecting Palo Alto traffic via Syslog. I'm then shooting it up to a single indexer that has both the Palo Alto App & Add-On.

[monitor:palo_logs.log]
sourcetype = pan:log
source = syslog
host = x.x.x.x
disabled = false
interval = 600    

While I can search through the data as though it were any other Splunk log, the Palo Alto APP & Add-On are not recognizing or transforming the data. Meaning I do not see any events or dashboards in those apps.

Also the sourcetype = pan:log in splunk. However the documentation specifies other source types:

Palo Alto Add-On Documentation

If someone can help me determine what I'm doing wrong, I would appreciate.

0 Karma

Eric_Mcknight
Explorer

Thanks to validate:

  1. Make sure the add-on is installed on your forwarder.
  2. Me personally, i install the app and add-on on my HEAVY forwarder syslog server, and don't install it on my indexers. Actually reduces indexer load by quite a bit.
  3. Make sure the app and add-on are installed on your search head.
0 Karma

tentontitan
New Member

Interesting. I'm currently using a universal forwarder to send data to Splunk. But you're saying that won't work. And that I have to use the heavy forwarder to forward and send the data properly. That way the transformations take place on the heavy forwarder and send it to your indexer.

I'll need to experiment.

0 Karma

Eric_Mcknight
Explorer

Things to check:

  1. Configuration looks just fine.
  2. Make sure the add-on is installed on your forwarder.
  3. Make sure the APP and Add-on are installed on your search heads.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...