Getting Data In

HF not send the logs to Splunk Cloud instance

Unnamed16
Loves-to-Learn

Hi Splunkers,

 

i already done configuration of HF and install uf credentials. but i can't see the logs of palo alto in Splunk Cloud 

 

for HF

Spoiler
 

Inputs.conf

[udp://5000]

index = xxxxx_pan

disabled = false

sourcetype = pan_log

 

but HF and Splunk Cloud instance have communicating. 

Spoiler
Unnamed16_0-1706158052825.png

 



please help me 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Are you sure your events are properly reaching your HF and are received by the HF?

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...