Getting Data In

How to get URL filtering logs from Palo Alto into Splunk?

craigmueller
New Member

Hello,
I am trying to find out how to get URL filtering logs from a Palo Alto into Splunk.

I do not see a URL filter log option in the "Log Forwarding Profile"

I have the Palo Alto plug-in installed in Splunk.

If it matters, I am using Splunk 6.1.

Thanks!

Tags (3)
0 Karma

mbenwell
Communicator

You don't need to do anything special with the Palo Splunk App

Assuming you have the appropriate security policy configured for url filtering, and that same policy is configured to forward syslog messages correctly.

There are a couple of things to look at. Most of the url logs are informational events. Check your syslog profile is set to send informational events.

Also in the URL filtering configuration (Objects>security profiles>URL filtering). Set the desired categories to an action of 'alert' and it will syslog them out.

Then in splunk they will appear as a sourcetype of "pan_threat"

There is also an option to 'log container page only' which will not log all content. Uncheck that and you should get everything.

0 Karma

craigmueller
New Member

@mbenwell

I know this is more of a PA question but, can you set up alerting for URLs on the URL Filtering Profile block list?

0 Karma

mbenwell
Communicator

I don't use the profile Block List text box, so can't really answer for that specific use. Usually setting the action to block should send a syslog message

If it doesn't log using the block list text box in the URL profile, you could try creating a custom category and add that to the URL profile.

0 Karma

ppablo
Retired

Hi @craigmueller

By "Palo Alto plug-in", are you referring to the Splunk for Palo Alto Networks app (https://apps.splunk.com/app/491/ ) or the TA-paloalto for the Splunk App for Enterprise Security (https://apps.splunk.com/app/263/ )?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...