All Apps and Add-ons

palo alto app

gisnetsec
Explorer

the palo alto app is not making use of the regular data files, can you help me to configure the data source?

0 Karma
1 Solution

kbains
Splunk Employee
Splunk Employee

sourcetype should be pan_log.

View solution in original post

kbains
Splunk Employee
Splunk Employee

sourcetype should be pan_log.

gisnetsec
Explorer

Just upgraded to 1.2 (thanks), but still no data.

0 Karma

kbains
Splunk Employee
Splunk Employee

Are you using the latest version of the app (1.2)?

0 Karma

kbains
Splunk Employee
Splunk Employee

You need to set the sourcetype to ns_log in your inputs.conf stanza. If you post your inputs.conf stanza, I can verify it is set correctly.

0 Karma

kbains
Splunk Employee
Splunk Employee

I think we should take this offline, could you email bd-labs@splunk.com and we can continue the discussion via email?

0 Karma

gisnetsec
Explorer

how is the app mapped to the ns_log sourcetype?

0 Karma

gisnetsec
Explorer

I just updated the sourcetype and here is that inputs.conf


[udp://2514]
connection_host = ip
sourcetype = ns_log
no_appending_timestamp = true

I restarted splunk an hour ago and still no data in any PaloAlto dash

0 Karma
Get Updates on the Splunk Community!

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...