All Apps and Add-ons

pantag action to multiple firewall cluster

alikapucu
Explorer

Hello, How can i push ip addresses (pantag) to multiple firewalls on one search call.

I have 3 different firewall clusters and when i have ip address on my splunk search i would like to push that ip address to multiple firewalls.

For example; Can i have a static config when i say device=border-firewalls command will actually run on multiple firewalls?
Or Can i run multiple pantag commands back to back on one search.

0 Karma
1 Solution

btorresgil
Builder

Hello! IP address tags use the same system in the firewall as User-ID mappings, so, ever since PAN-OS 8.0 you can redistribute the IP tags between firewalls the same way as users. Basically, you tell all the firewalls to share user/tag mappings, then tag the IP addresses on the main User-ID Agent firewall (or Panorama). The tag will automatically be redistributed to all other firewalls you've configured to receive it. This way, Splunk only needs to connect to one Firewall or Panorama to effectively create a new tag on all firewalls.

More information:

View solution in original post

0 Karma

btorresgil
Builder

Hello! IP address tags use the same system in the firewall as User-ID mappings, so, ever since PAN-OS 8.0 you can redistribute the IP tags between firewalls the same way as users. Basically, you tell all the firewalls to share user/tag mappings, then tag the IP addresses on the main User-ID Agent firewall (or Panorama). The tag will automatically be redistributed to all other firewalls you've configured to receive it. This way, Splunk only needs to connect to one Firewall or Panorama to effectively create a new tag on all firewalls.

More information:

0 Karma

alikapucu
Explorer

Thank you that did the trick

0 Karma

btorresgil
Builder

Great! Glad to hear it!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...