All Apps and Add-ons

Splunk for Palo Alto

lazhar
New Member

Hi,

I am using Splunk for Palo Alto application to collect and correlate logs coming from my PANs, i am able now to see the 4 types of Palo Alto Logs (Threat, Traffic, Configuration and System),
Now that i have my Threat Dashboard and reports, i would like to differentiate virus, spyware and vulnerabilities logs, How can i do this?

Thanks
Lazhar

Tags (1)
0 Karma
1 Solution

MarioM
Motivator

One of the app's field extraction is "log_subtype" which contains those different types:

Then you could filter your searches on those

sourcetype="pan_threat" log_subtype="vulnerability" OR log_subtype="virus" OR log_subtype="spyware" | top dst_user by log_subtype

OR

filter on each one of those

sourcetype="pan_threat" log_subtype="vulnerability" | top dst_user by app

View solution in original post

MarioM
Motivator

One of the app's field extraction is "log_subtype" which contains those different types:

Then you could filter your searches on those

sourcetype="pan_threat" log_subtype="vulnerability" OR log_subtype="virus" OR log_subtype="spyware" | top dst_user by log_subtype

OR

filter on each one of those

sourcetype="pan_threat" log_subtype="vulnerability" | top dst_user by app
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...