Hey there! The documentation for configuring the PAN Add-on (found at splunk.paloaltonetworks.com) mentions that TCP/UDP data sources must be configured to get data out of our PAN firewalls; however, Splunk support informed me that this isn't possible due to security restrictions on Splunk Cloud instances. However, without these data sources, I'm not really sure how else to get data into our Splunk Cloud environment (they've mentioned that we can use an HTTP event collector, but the documentation doesn't say much on how to do that).
Has anyone else successfully connected their PAN firewalls/WIldfire to Splunk Cloud, and if so, would you be willing to advise me on how to do so?
Thanks!!,
... View more