Getting Data In

Palo Alto stopped logging traffic to Splunk

dkr3500
Path Finder

I am having the same issue as: https://answers.splunk.com/answers/507167/why-are-my-palo-alto-firewall-logs-not-forwarding.html . Palo Alto has stopped logging traffic to Splunk after we performed an OS patch (RHEL 7.5) on the Splunk server and then performed a reboot on the Splunk server - in this case a search head. The splunkd.log didn't reveal anything other than the fact that it stopped sending messages after the Splunk server reboot.

No changes were made to the PA firewall appliance nor any sort of configuration changes on the Splunk server prior to the patch/reboot. Everything was working fine prior to the patch and reboot - which is still working, other than the PA logs. A systemctl status splunk shows that all services are enabled, active and dislays what you would expect.

There isn't much information on the forums regarding this specific topic, any help would be greatly appreciated.

Tags (1)
0 Karma

renjith_nair
Legend

random checks ; was your on RHEL 7.x earlier? do you have SELinux enabled or the splunk user still have access to the log files? Are you using firewalld or your firewalld get enabled after the reboot?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...