Platform: Splunk and Palo Alto Networks App/Add-on latest release.
Following the installation instructions it looks like you can configure the Palo Alto Networks App/Add-on to a custom index. If I perform a search: index=my_custom_index eventtype=pan within the Add-On, it works. Without indicating the index, it does not.
On top of that the App is unable to populate the dashboards. I have added the local/inputs.conf to the App and Add-on with the configuration:
App version 5.x/6.x with Add-on
[udp://514]
connection_host = ip
index = network
sourcetype = pan:log
no_appending_timestamp = true
But no luck. Has anyone experienced something similar?
Thanks,
D
... View more