Deployment Architecture

How to exclude firewall events in Splunk?

umesh
Path Finder

Hi

i am using palo-alto firewall. i am getting firewall logs to syslog server and monitoring those logs and forwarding to indexer and to search head.

I want to exclude events from particular src_ip from indexing as the src is generating high volume of logs and consuming my license.

How to exclude these events. Please let me know. 

Thanks

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @umeshm,

when I speak of location I don't mean on file system, that isn't relevant, but the server where i located: they must be on Indexers or, when present on Heavy Forwarders (as I suppose you have).

Is it clear for you how to configure your filter?

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @umesh,

to filter and discard events you have to find a regex and apply the configurations described at https://docs.splunk.com/Documentation/Splunk/9.0.1/Forwarding/Routeandfilterdatad#Filter_event_data_...

remember that these configuration must be applied on Indexers or, when present, on heavy Forwarders.

Ciao.

Giuseppe

0 Karma

umesh
Path Finder

 

@gcusello 

[pan:traffic]

location of props.conf and tranforms.conf is etc/system local  or Splunk add-on for paloalto app. which is preferable .

 

Thanks for the quick response 

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @umeshm,

when I speak of location I don't mean on file system, that isn't relevant, but the server where i located: they must be on Indexers or, when present on Heavy Forwarders (as I suppose you have).

Is it clear for you how to configure your filter?

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...