Hi,
Cann anyone confirm if PAN-OS 8.1 is compatible with the Splunk APP. I can only see data in splunk if the input is set to syslog and not pan:log. I have another PAN 8.0 device configured and that is working ok with pan:log.
Thanks
Ady
PAN-OS 8.1 is supported in the app.
Double check your input.conf it should look like this
## App version 5.x/6.x with Add-on
[udp://514]
sourcetype = pan:log
no_appending_timestamp = true
Feel free to review the documentation about adding the input
https://splunk.paloaltonetworks.com/firewalls-panorama-and-traps.html