All Apps and Add-ons

Support for the 'Authentication' and 'Network Session' data models on the Splunk_TA_paloalto

jwiedow
Communicator

Are there plans to add support for the 'Network Sessions' and 'Authentication' CIM data models from the Splunk_TA_paloalto Add-on for globalprotect events?

1 Solution

btorresgil
Builder

Yes, there are plans to do this and other improvements to CIM datamodel for better ES integration. Keep an eye out in the next couple Add-on releases. Thanks for the feedback!

View solution in original post

btorresgil
Builder

Yes, there are plans to do this and other improvements to CIM datamodel for better ES integration. Keep an eye out in the next couple Add-on releases. Thanks for the feedback!

jwiedow
Communicator

Thank you Brian. Do you have a road map or a time frame for when this support will be added?

0 Karma

saurabh_tek11
Communicator

Its been 2 years for this answer! @btorresgil

0 Karma

btorresgil
Builder

Hi saurabh_tek11, thanks for bumping this. We support network sessions, see eventtype=pan_traffic_start and pan_traffic_end. We could support Authentication to some extent with USERID type logs from the firewall, but the Authentication CIM is not a great fit because it's geared more toward the logs from the actual point of authentication, which the firewall typically is not in enterprise environments. This would be your RADIUS, LDAP, or AD server usually.

I opened a feature request so you can share your use cases for supporting the Authentication CIM. I'm very interested in any feedback, thanks!
https://github.com/PaloAltoNetworks/Splunk_TA_paloalto/issues/33

0 Karma

florin
Observer

tcp start and end are not suppose to be mapped to Network Sessions Datamodel (CIM) according to Splunk:
https://docs.splunk.com/Documentation/CIM/5.3.1/User/NetworkSessions:

"The fields in the Network Sessions data model describe Dynamic Host Configuration Protocol (DHCP) and Virtual Private Network (VPN) traffic, whether server:server or client:server, and network infrastructure inventory and topology."

Globalprotect logs should be the ones mapped to Network Sessions - VPN

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...