the palo alto app is not making use of the regular data files, can you help me to configure the data source?
sourcetype should be pan_log.
Just upgraded to 1.2 (thanks), but still no data.
Are you using the latest version of the app (1.2)?
You need to set the sourcetype to ns_log in your inputs.conf stanza. If you post your inputs.conf stanza, I can verify it is set correctly.
I think we should take this offline, could you email bd-labs@splunk.com and we can continue the discussion via email?
how is the app mapped to the ns_log sourcetype?
I just updated the sourcetype and here is that inputs.conf
[udp://2514]
connection_host = ip
sourcetype = ns_log
no_appending_timestamp = true
I restarted splunk an hour ago and still no data in any PaloAlto dash