We have a central syslog server that is being used to push paloalto logs to along with some other devices, each host has its own folder on the syslog server where data for that particular host is stored. From a splunk POV we are a cloud hosted customer.
I have today installed the palo alto app for Splunk and wondering on the best way to achieve the below.
As the data is coming into the index=syslog and sourcetype=syslog the inputs on the app are not working as is expecting particular sourcetypes pan_logs as an example.
Is it possible to override and redirect the PA hosts from the syslog stream to the correct index and sourcetype ?
Is it possible to filter out the