All Apps and Add-ons

Splunk and Palo Alto Cortex Data Lake: Data for global protect cloud service is not getting parsed.

shirishkamat84
Path Finder

We are ingesting the firewall data from the panorama and GP cloud service logs from Cortex and ingesting the data to the same index pan_logs with sourcetype=pan:log.

The logs from panorama are getting parsed properly, however, the data from the cortex data lake for global protect cloud service is not getting parsed. Does the Palo Alto Networks for Splunk add-on support data coming from Cortex? Any suggestions to make this work?

Labels (1)

swebb07g
Path Finder

I'm also curious about this.

0 Karma

hiren53
New Member

I am trying to get data from cortex data lake to our Splunk hosted on prem. We getting the logs but it’s garbage characters.

splunk is not able to open ssl input. Can you share splunk side config to make this work?

what were the parameters on inputs.conf and what third party CA you user and created pem files?

 

any help would be appreciated 

0 Karma

swebb07g
Path Finder

I don't think Cortex Data Lake supports SSL (assuming you mean https). It does support syslog over TLS though.

0 Karma

swebb07g
Path Finder

In case anyone else lands here, it appears Cortex Data Lake now supports forwarding directly to Splunk  via HTTP Event Collector (HEC).

https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-start...

0 Karma
Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...