All Apps and Add-ons

Splunk PaloAlto App with SYSLOG

avid_splunker
Loves-to-Learn Everything

We have a central syslog server that is being used to push paloalto logs to along with some other devices, each host has its own folder on the syslog server where data for that particular host is stored.  From a splunk POV we are a cloud hosted customer. 

I have today installed the palo alto app for Splunk and wondering on the best way to achieve the below. 

As the data is coming into the index=syslog and sourcetype=syslog the inputs on the app are not working as is expecting particular sourcetypes pan_logs  as an example.

Is it possible to override and redirect the PA hosts from the syslog stream to the correct index and sourcetype ? 

 

Is it possible to filter out the 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...