Hello guys I installed Palo Alto Add on On Port udp and sourcetype any udp port like 10551 and sourcetype replace [fortigate_log] with [fortigate], for instance. as mentioned in documentation but I could
| fortigate_traffic | 57,644 | 96.385% | |
| fortigate_utm | 1,766 | 2.953% | |
| fortigate_event | 396 | 0.662% |
get this sourcetypes and this addon do not creates tags for datamodels. Please say me solution to have this sourcetypes what I configured wrong? https://splunkbase.splunk.com/app/2846
Could you please check your props.conf using btool and provide the output here?
Furthermore, on which instance have you opened the ports? Is it on a Heavy Forwarder?
On which instances have you installed the add-on?