Splunk Enterprise Security

Palo Alto app Dashboard not showing any data.

amksa
Explorer

Hello Folks,

Please I am having an issue where my PA app is not showing events and I am able to run searches and find some results :

Background : I have moved all the VMs where we have our Splunk servers to different VLAN.
After we did that our PA app is not parsing the data anymore.
1-for example : eventtype=pan this working properly and I can see the logs. the issue is that most of the logs are TRAFFIC logs. Looked for THREAT for example nothing.
2-We updated to the latest app and we can setup the sourcetype= pan:log
our input file :
[monitor:///apps/splunk_logs/panw/E*/panw.log]
sourcetype = pan:log
index = pan_logs
host_segment = 4

ignoreOlderThan = 30d

disabled = false

We can see the sourcetype pan:log in the search results but not the others such as pan:threats, pan:config and so forth.
2-for the inputs file we have a deployment app that we're using and we have it as above.
3-I tried installing the app and the add-on locally and I have created /local/inputs.conf and added same info as above and still nothing is showing.

Please Advise?

Thanks!

0 Karma

BrendanCO
Path Finder

Can you please expound on that update? What does "adding TA" mean?

0 Karma

amksa
Explorer

I have fixed this issue by adding the TA to the HF and indexers all of the ones I have and it worked.

0 Karma

amksa
Explorer

To be more specific, I did run another search : index=pan_logs "vulnerability" and I was able to find THREAT logs as needed. note sure what is missing.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...