All Apps and Add-ons

palo alto app

gisnetsec
Explorer

the palo alto app is not making use of the regular data files, can you help me to configure the data source?

0 Karma
1 Solution

kbains
Splunk Employee
Splunk Employee

sourcetype should be pan_log.

View solution in original post

kbains
Splunk Employee
Splunk Employee

sourcetype should be pan_log.

gisnetsec
Explorer

Just upgraded to 1.2 (thanks), but still no data.

0 Karma

kbains
Splunk Employee
Splunk Employee

Are you using the latest version of the app (1.2)?

0 Karma

kbains
Splunk Employee
Splunk Employee

You need to set the sourcetype to ns_log in your inputs.conf stanza. If you post your inputs.conf stanza, I can verify it is set correctly.

0 Karma

kbains
Splunk Employee
Splunk Employee

I think we should take this offline, could you email bd-labs@splunk.com and we can continue the discussion via email?

0 Karma

gisnetsec
Explorer

how is the app mapped to the ns_log sourcetype?

0 Karma

gisnetsec
Explorer

I just updated the sourcetype and here is that inputs.conf


[udp://2514]
connection_host = ip
sourcetype = ns_log
no_appending_timestamp = true

I restarted splunk an hour ago and still no data in any PaloAlto dash

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...