Getting Data In

To ingest Palo Alto Traffic and Threat logs into Splunk, should syslog-ng or HF (via the Palo Alto Network Add-on)?

adnankhan5133
Communicator

Initially, I was just planning to install the Palo Alto Network Add-on for Splunk on an HF, and get the traffic and threat logs sent to Splunk, but there also appears to be a lot of documentation for using a syslog server + UF to facilitate the flow of Palo Alto logs to Splunk.

 

What is the recommended approach to send Palo Alto logs to Splunk? I'm mainly interested in just getting firewall (pan:traffic) and IDS/IPS (pan:threat) logs.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...