Splunk Enterprise

How to list the changed made to Palo Alto Firewall ACL rules?

Golgie
Loves-to-Learn Lots

I need to be able to list the changes made to firewall rules.

It seems like a simple audit task that you should be able to do but unfortunately, I can't find the answer to my problem from these documentations. 

Does anyone know how to do this audit from splunk? 

Palo Alto Networks App for Splunk | Splunkbase
Palo Alto Networks Add-on for Splunk | Splunkbase

Labels (2)
0 Karma

JRW
Splunk Employee
Splunk Employee

There should be a sequence_number field in the config logs that can be correlated with the other logs of the same number to list the changes made to firewall rules

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...