Getting Data In

SourceType 'pan_log' not listed when adding new DataInput for PaloAlto

gooon26
New Member

Hi

When i try to configure a new UDP data input in my splunk to work with PaloAlto it only list these source types

Access_combined
apache_error
csv
iis
log4j
log4php
syslog

How can i install the sourcetype 'pan_log'

Best regard

Gonzalo

0 Karma

radam2000
Path Finder

Actually i believe you need to install the paloalto add-on instead of the app

Splunk_TA_paloalto

Now at version 6.1.1 i believe

0 Karma

rgaleone1
Path Finder

Have you installed the Palo Alto App?

0 Karma

matthieulopez
Engager

same problem
do you find an issue?

0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...