Splunk Enterprise

PALOALTO

Apolo1999
New Member

In our infra we collect the logs with paloalto, epo, proxy ..., everything works fine except the log collection of Palo Alto.   we changed the queue module (queue.type = "LinkedList") and we moved to the direct queue (queue.type = "Direct") but it's not good enough. So we want to know if it fits or not or is it a problem of conf that we have not seen? -------------------------------------------------------------------------

Labels (2)
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...