All Apps and Add-ons

Splunk for Palo Alto Networks: Why am I not getting any data in the pan_logs index?

arcticgenes
New Member

I'm experiecing an issue with getting data into my splunk index for pan_logs.

It was working for a time and then something changed. I can see the logs hitting my heavy forwarders if I do a tcpdump on the port the inputs.conf stanza is configured for. I have the palo alto app installed on the heavy forwarder to process all the transforms and props. The problem is the i'm not getting any data into the pan_logs index. I have tried updating the app on the heavy forwarder but no luck. The index exists.

Any suggestions?

0 Karma

neelamssantosh
Contributor

Check with search: index=** sourcetype=pan*
then figure out to which index data is being indexed to.
unable to type single asterisk sign
Hope it will help.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...