Getting Data In

Palo Alto stopped logging traffic to Splunk

dkr3500
Path Finder

I am having the same issue as: https://answers.splunk.com/answers/507167/why-are-my-palo-alto-firewall-logs-not-forwarding.html . Palo Alto has stopped logging traffic to Splunk after we performed an OS patch (RHEL 7.5) on the Splunk server and then performed a reboot on the Splunk server - in this case a search head. The splunkd.log didn't reveal anything other than the fact that it stopped sending messages after the Splunk server reboot.

No changes were made to the PA firewall appliance nor any sort of configuration changes on the Splunk server prior to the patch/reboot. Everything was working fine prior to the patch and reboot - which is still working, other than the PA logs. A systemctl status splunk shows that all services are enabled, active and dislays what you would expect.

There isn't much information on the forums regarding this specific topic, any help would be greatly appreciated.

Tags (1)
0 Karma

renjith_nair
Legend

random checks ; was your on RHEL 7.x earlier? do you have SELinux enabled or the splunk user still have access to the log files? Are you using firewalld or your firewalld get enabled after the reboot?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...