All Apps and Add-ons

Splunk PaloAlto App with SYSLOG

avid_splunker
Loves-to-Learn Everything

We have a central syslog server that is being used to push paloalto logs to along with some other devices, each host has its own folder on the syslog server where data for that particular host is stored.  From a splunk POV we are a cloud hosted customer. 

I have today installed the palo alto app for Splunk and wondering on the best way to achieve the below. 

As the data is coming into the index=syslog and sourcetype=syslog the inputs on the app are not working as is expecting particular sourcetypes pan_logs  as an example.

Is it possible to override and redirect the PA hosts from the syslog stream to the correct index and sourcetype ? 

 

Is it possible to filter out the 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...

Introducing New Splunkbase Governance!

Splunk apps are essential for maximizing the value of your Splunk Experience. Whether you’re using the default ...