All Apps and Add-ons

Received event for unconfigured/disabled/deleted

Finisar
New Member

I have configured the above settings as described, I see the below msg. Are there are any more settings that needs to be done to capture the events.

received event for unconfigured/disabled/deleted index='pan_log' with source='source::udp:514' host='host::xx.xx.xx.xx' sourcetype='sourcetype::pan_threat' (1 missing total)

0 Karma

Finisar
New Member

Ya, thanks a lot for correcting me.

0 Karma

monzy
Communicator

Your error is probably due to a typo in your inputs.conf file. The Palo alto apps index is pan_logs and not the singular pan_log. Please edit your inputs.conf.

Cheers,

Monzy

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...