All Apps and Add-ons
Highlighted

Question about Palo Alto Network

New Member

Dear Splunkers,
I have installed Splunk for Palo Alto Network app, Do you have a manual how to install. Should I have to configure syslog on Palo Alto Device?

Regards,

Jose Rivera

0 Karma
Highlighted

Re: Question about Palo Alto Network

Communicator

Hello Jose,

There are instructions on the apps page. Short version, you will have to configure your Palo Alto firewall to forward to a Splunk sever. On the Splunk side, you will have to configure an input. The readme file in the apps directory has a sample inputs.conf stanza.

Cheers,

Monzy

(Typing with thumbs)

lets say that the PaloAlto is sending logs to UDP 5155 (the default is udp 514), here's a sample stanza for your inputs.conf

[udp://5155]

index= pan_logs

connection_host = ip

sourcetype = pan_log

no_appending_timestamp = true