Getting Data In

Palo Alto Networks config logs not showing before and after info

heathramos
Path Finder

We forward all config logs from our Palo Alto Networks firewall directly into Splunk

I can see that the config logs show up in Splunk but I don't see any info on the before and after change fields

when I look at the source within Splunk, that info isn't in it but it shows in the PAN config logs on the firewall itself

I want to create a report that within Splunk that shows all firewall config changes, including the before and after (kind of pointless without it).

any idea what is wrong?

Heath

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...