Hi,
I'm using Splunk Cloud and trying to get the Splunk for Palo Alto app running, but I'm sure this issue applies to other apps. Since we need a tcp/udp input, I created a universal forwarder and installed the PAN app on my cloud search head.
I get the pan logs forwarding, but the source types are not being created like the transforms should do. If I try to unzip the PAN app on the forwarder, nothing flows.
I read that the forwarder does not process the transforms anyway, but rather, it should be on my indexer. But in the cloud, I don't have any way to install the PAN app on my indexer. Does anyone know how to get the PAN app (or others) to handle the transforms?
In the Cloud UI for settings, I can find that transform listed and the regex matches a raw line, but it doesn't assign it to the right source type. I'm assuming that's because the PAN app is not on my indexer.
Has anyone ran into this before and know what to do?
Thank you!
Steve
... View more