Splunk Enterprise

PALOALTO

Apolo1999
New Member

In our infra we collect the logs with paloalto, epo, proxy ..., everything works fine except the log collection of Palo Alto.   we changed the queue module (queue.type = "LinkedList") and we moved to the direct queue (queue.type = "Direct") but it's not good enough. So we want to know if it fits or not or is it a problem of conf that we have not seen? -------------------------------------------------------------------------

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...