All Apps and Add-ons

Yes, another person with Palo Alto dashboard issues...

BrendanCO
Path Finder

All,
I’m not getting consistent data within the dashboards and in some cases, no data in multiple dashboards within the Palo Alto App for Splunk. I could really use a sanity check!
To cover the basics:
• Followed the installation Debian Linux instructions step by step. All seemed to be good.
• Set up Splunk’s Data Input – UDP – 514 – pan:log
• Have my PAN FW’s forwarding syslog to my Splunk instance. Data seems to be coming in fine.
• To test I search for eventtype=pan and I’m getting good results.
My /opt/splunk/etc/apps/Splunk_TA_paloalto/default/inputs.conf looks like


[udp://514]
connection_host = ip
sourcetype = pan:log
no_appending_timestamp = true
disabled = 0


To make sure there weren’t conflicting inputs.conf I commented out: /opt/splunk/etc/apps /SplunkforPaloAltoNetworks/local/inputs.conf
I check the entire file structure and user:group for all apps is splunk:splunk

Thoughts?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...