All Apps and Add-ons

palo alto app

gisnetsec
Explorer

the palo alto app is not making use of the regular data files, can you help me to configure the data source?

0 Karma
1 Solution

kbains
Splunk Employee
Splunk Employee

sourcetype should be pan_log.

View solution in original post

kbains
Splunk Employee
Splunk Employee

sourcetype should be pan_log.

gisnetsec
Explorer

Just upgraded to 1.2 (thanks), but still no data.

0 Karma

kbains
Splunk Employee
Splunk Employee

Are you using the latest version of the app (1.2)?

0 Karma

kbains
Splunk Employee
Splunk Employee

You need to set the sourcetype to ns_log in your inputs.conf stanza. If you post your inputs.conf stanza, I can verify it is set correctly.

0 Karma

kbains
Splunk Employee
Splunk Employee

I think we should take this offline, could you email bd-labs@splunk.com and we can continue the discussion via email?

0 Karma

gisnetsec
Explorer

how is the app mapped to the ns_log sourcetype?

0 Karma

gisnetsec
Explorer

I just updated the sourcetype and here is that inputs.conf


[udp://2514]
connection_host = ip
sourcetype = ns_log
no_appending_timestamp = true

I restarted splunk an hour ago and still no data in any PaloAlto dash

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...