Hello,
Current setup is Palo Alto firewall and using Sc4s (splunk connect for syslog) , so far getting all logs for Palo Alto except for wildfire. Can someone tell me do we need the apps or add-ons to be able to create good detections for the firewall ? if so Can someone tell me what apps and add-ons should be used and do they have to be configured? Getting my information for here: https://pan.dev/splunk/docs/
Regards,
@hl - This document describe many detection that would apply to Palo Alto data or Firewall data in general.
https://research.splunk.com/detections/categories/network/
I hope this helps!!! Kindly upvote if it does!!!