All Apps and Add-ons

Splunk and Palo Alto Cortex Data Lake: Data for global protect cloud service is not getting parsed.

shirishkamat84
Path Finder

We are ingesting the firewall data from the panorama and GP cloud service logs from Cortex and ingesting the data to the same index pan_logs with sourcetype=pan:log.

The logs from panorama are getting parsed properly, however, the data from the cortex data lake for global protect cloud service is not getting parsed. Does the Palo Alto Networks for Splunk add-on support data coming from Cortex? Any suggestions to make this work?

Labels (1)

swebb07g
Path Finder

I'm also curious about this.

0 Karma

hiren53
New Member

I am trying to get data from cortex data lake to our Splunk hosted on prem. We getting the logs but it’s garbage characters.

splunk is not able to open ssl input. Can you share splunk side config to make this work?

what were the parameters on inputs.conf and what third party CA you user and created pem files?

 

any help would be appreciated 

0 Karma

swebb07g
Path Finder

I don't think Cortex Data Lake supports SSL (assuming you mean https). It does support syslog over TLS though.

0 Karma

swebb07g
Path Finder

In case anyone else lands here, it appears Cortex Data Lake now supports forwarding directly to Splunk  via HTTP Event Collector (HEC).

https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-start...

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...