The Prisma Cloud Compute Splunk App allows high priority security incidents and forensic data from Prisma Cloud to be ingested by Splunk.
The app adds two main components to your Splunk deployment: scripted data inputs that make use of your Prisma Cloud Compute capabilities API to pull incidents and forensics and a sample Splunk dashboard that presents that data.
If you have any questions about usage, please refer to the README.md here:
https://github.com/PaloAltoNetworks/prisma-cloud-compute-splunk
If the README does not answer your questions, feel free to open an issue here:
https://github.com/PaloAltoNetworks/prisma-cloud-compute-splunk/issues
Please read SUPPORT.md for details on how to get support for this project:
https://github.com/PaloAltoNetworks/prisma-cloud-compute-splunk/blob/main/SUPPORT.md