Splunk Enterprise Security

Splunk Add on for PA - incorrect tagging of Network sessions

lakshman239
Influencer

** This is not a question, but adding this info for awareness for people using PA and CIM **

The default/tags.conf for start and end eventtypes is incorrect. It should be as follows:
[eventtype=pan_traffic_start]
network = enabled
communicate=enabled
start = enabled
session = disabled

[eventtype=pan_traffic_end]
network = enabled
communicate=enabled
end = enabled
session = disabled

0 Karma

lakshman239
Influencer
0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...